An official Admiresty Corporation service
How to verify
Official Admiresty services use admiresty.co

Admiresty Corporation operates ThreatGrid and its full service ecosystem from admiresty.co. All official platforms run from this domain or a verified subdomain. If you’re unsure, visit admiresty.co directly to confirm.

Secure Admiresty services always use HTTPS

A padlock and https:// in your address bar confirm a safe, encrypted connection. Never enter credentials or share sensitive data on any page without a valid HTTPS connection to an Admiresty domain.

Security Bulletins

Active threat advisories and known exploited vulnerabilities.

Pulled daily from the CISA Known Exploited Vulnerabilities catalog. Every entry has confirmed active exploitation in the wild. Last synced Sep 16, 2026.

1,713 total bulletins 1,713 critical or high severity Source: CISA KEV + NVD
Critical CVE-2019-0863 Microsoft · Windows Added Nov 3, 2021

Microsoft Windows Error Reporting (WER) Privilege Escalation Vulnerability

Microsoft Windows Error Reporting (WER) contains a privilege escalation vulnerability due to the way it handles files, allowing for code execution in kernel mode.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2021-36955 Microsoft · Windows Added Nov 3, 2021

Microsoft Windows Common Log File System (CLFS) Driver Privilege Escalation Vulnerability

Microsoft Windows Common Log File System (CLFS) driver contains an unspecified vulnerability that allows for privilege escalation.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2021-38648 Microsoft · Open Management Infrastructure (OMI) Added Nov 3, 2021

Microsoft Open Management Infrastructure (OMI) Privilege Escalation Vulnerability

Microsoft Open Management Infrastructure (OMI) within Azure VM Management Extensions contains an unspecified vulnerability allowing privilege escalation.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2020-6819 Mozilla · Firefox and Thunderbird Added Nov 3, 2021

Mozilla Firefox And Thunderbird Use-After-Free Vulnerability

Mozilla Firefox and Thunderbird contain a race condition vulnerability when running the nsDocShell destructor under certain conditions. The race condition creates a use-after-free vulnerability, causing unspecified impacts.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2020-6820 Mozilla · Firefox and Thunderbird Added Nov 3, 2021

Mozilla Firefox And Thunderbird Use-After-Free Vulnerability

Mozilla Firefox and Thunderbird contain a race condition vulnerability when handling a ReadableStream under certain conditions. The race condition creates a use-after-free vulnerability, causing unspecified impacts.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2019-17026 Mozilla · Firefox and Thunderbird Added Nov 3, 2021

Mozilla Firefox And Thunderbird Type Confusion Vulnerability

Mozilla Firefox and Thunderbird contain a type confusion vulnerability due to incorrect alias information in the IonMonkey JIT compiler when setting array elements.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2019-15949 Nagios · Nagios XI Added Nov 3, 2021

Nagios XI Remote Code Execution Vulnerability

Nagios XI contains a remote code execution vulnerability in which a user can modify the check_plugin executable and insert malicious commands to execute as root.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2020-26919 NETGEAR · JGS516PE Devices Added Nov 3, 2021

Netgear JGS516PE Devices Missing Function Level Access Control Vulnerability

Netgear JGS516PE devices contain a missing function level access control vulnerability.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2019-19356 Netis · WF2419 Devices Added Nov 3, 2021

Netis WF2419 Devices Remote Code Execution Vulnerability

Netis WF2419 devices contains an unspecified vulnerability that allows an attacker to perform remote code execution as root through the router's web management page.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2020-2555 Oracle · Multiple Products Added Nov 3, 2021

Oracle Multiple Products Remote Code Execution Vulnerability

Multiple Oracle products contain a remote code execution vulnerability that allows an unauthenticated attacker with network access via T3 or HTTP to takeover the affected system. Impacted Oracle products: Oracle Coherence in Fusion Middleware, Oracle Utilities Framework, Oracle Retail Assortment Planning, Oracle Commerce, Oracle Communications Diameter Signaling Router (DSR).

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2012-3152 Oracle · Fusion Middleware Added Nov 3, 2021

Oracle Fusion Middleware Unspecified Vulnerability

Oracle Fusion Middleware Reports Developer contains an unspecified vulnerability that allows remote attackers to affect confidentiality and integrity of affected systems.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2020-14871 Oracle · Solaris and Zettabyte File System (ZFS) Added Nov 3, 2021

Oracle Solaris and Zettabyte File System (ZFS) Unspecified Vulnerability

Oracle Solaris and Oracle ZFS Storage Appliance Kit contain an unspecified vulnerability causing high impacts to confidentiality, integrity, and availability of affected systems.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2015-4852 Oracle · WebLogic Server Added Nov 3, 2021

Oracle WebLogic Server Deserialization of Untrusted Data Vulnerability

Oracle WebLogic Server contains a deserialization of untrusted data vulnerability within Apache Commons, which can allow for for remote code execution.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2020-14750 Oracle · WebLogic Server Added Nov 3, 2021

Oracle WebLogic Server Remote Code Execution Vulnerability

Oracle WebLogic Server contains an unspecified vulnerability allowing an unauthenticated attacker to perform remote code execution. This vulnerability is related to CVE-2020-14882.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2020-14882 Oracle · WebLogic Server Added Nov 3, 2021

Oracle WebLogic Server Remote Code Execution Vulnerability

Oracle WebLogic Server contains an unspecified vulnerability, which is assessed to allow for remote code execution, based on this vulnerability being related to CVE-2020-14750.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2020-14883 Oracle · WebLogic Server Added Nov 3, 2021

Oracle WebLogic Server Unspecified Vulnerability

Oracle WebLogic Server contains an unspecified vulnerability in the Console component with high impacts to confidentilaity, integrity, and availability.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2020-8644 PlaySMS · PlaySMS Added Nov 3, 2021

PlaySMS Server-Side Template Injection Vulnerability

PlaySMS contains a server-side template injection vulnerability that allows for remote code execution.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2019-18935 Progress · Telerik UI for ASP.NET AJAX Added Nov 3, 2021

Progress Telerik UI for ASP.NET AJAX Deserialization of Untrusted Data Vulnerability

Progress Telerik UI for ASP.NET AJAX contains a deserialization of untrusted data vulnerability through RadAsyncUpload which leads to code execution on the server in the context of the w3wp.exe process.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2021-22893 Ivanti · Pulse Connect Secure Added Nov 3, 2021

Ivanti Pulse Connect Secure Use-After-Free Vulnerability

Ivanti Pulse Connect Secure contains a use-after-free vulnerability that allow a remote, unauthenticated attacker to execute code via license services.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2020-8243 Ivanti · Pulse Connect Secure Added Nov 3, 2021

Ivanti Pulse Connect Secure Code Execution Vulnerability

Ivanti Pulse Connect Secure contains an unspecified vulnerability in the admin web interface that could allow an authenticated attacker to upload a custom template to perform code execution.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2021-22900 Ivanti · Pulse Connect Secure Added Nov 3, 2021

Ivanti Pulse Connect Secure Unrestricted File Upload Vulnerability

Ivanti Pulse Connect Secure contains an unrestricted file upload vulnerability that allows an authenticated administrator to perform a file write via a maliciously crafted archive upload in the administrator web interface.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2021-22894 Ivanti · Pulse Connect Secure Added Nov 3, 2021

Ivanti Pulse Connect Secure Collaboration Suite Buffer Overflow Vulnerability

Ivanti Pulse Connect Secure Collaboration Suite contains a buffer overflow vulnerabilities that allows a remote authenticated users to execute code as the root user via maliciously crafted meeting room.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2020-8260 Ivanti · Pulse Connect Secure Added Nov 3, 2021

Ivanti Pulse Connect Secure Code Execution Vulnerability

Pulse Connect Secure contains an unspecified vulnerability that allows an authenticated attacker to perform code execution using uncontrolled gzip extraction.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2021-22899 Ivanti · Pulse Connect Secure Added Nov 3, 2021

Ivanti Pulse Connect Secure Command Injection Vulnerability

Ivanti Pulse Connect Secure contains a command injection vulnerability that allows remote authenticated users to perform remote code execution via Windows File Resource Profiles.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2019-11510 Ivanti · Pulse Connect Secure Added Nov 3, 2021

Ivanti Pulse Connect Secure Arbitrary File Read Vulnerability

Ivanti Pulse Connect Secure contains an arbitrary file read vulnerability that allows an unauthenticated remote attacker with network access via HTTPS to send a specially crafted URI.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed

Need help prioritizing these vulnerabilities?

ThreatGrid can assess your environment and map active CVEs to your monitored assets.