An official Admiresty Corporation service
How to verify
Official Admiresty services use admiresty.co

Admiresty Corporation operates ThreatGrid and its full service ecosystem from admiresty.co. All official platforms run from this domain or a verified subdomain. If you’re unsure, visit admiresty.co directly to confirm.

Secure Admiresty services always use HTTPS

A padlock and https:// in your address bar confirm a safe, encrypted connection. Never enter credentials or share sensitive data on any page without a valid HTTPS connection to an Admiresty domain.

Security Bulletins

Active threat advisories and known exploited vulnerabilities.

Pulled daily from the CISA Known Exploited Vulnerabilities catalog. Every entry has confirmed active exploitation in the wild. Last synced Sep 16, 2026.

1,713 total bulletins 1,713 critical or high severity Source: CISA KEV + NVD
Critical CVE-2019-11539 Ivanti · Pulse Connect Secure and Pulse Policy Secure Added Nov 3, 2021

Ivanti Pulse Connect Secure and Policy Secure Command Injection Vulnerability

Ivanti Pulse Connect Secure and Policy Secure allows an authenticated attacker from the admin web interface to inject and execute commands.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2021-1906 Qualcomm · Multiple Chipsets Added Nov 3, 2021

Qualcomm Multiple Chipsets Detection of Error Condition Without Action Vulnerability

Multiple Qualcomm chipsets contain a detection of error condition without action vulnerability when improper handling of address deregistration on failure can lead to new GPU address allocation failure.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2021-1905 Qualcomm · Multiple Chipsets Added Nov 3, 2021

Qualcomm Multiple Chipsets Use-After-Free Vulnerability

Multiple Qualcomm Chipsets contain a use after free vulnerability due to improper handling of memory mapping of multiple processes simultaneously.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2020-10221 rConfig · rConfig Added Nov 3, 2021

rConfig OS Command Injection Vulnerability

rConfig lib/ajaxHandlers/ajaxAddTemplate.php contains an OS command injection vulnerability that allows remote attackers to execute OS commands via shell metacharacters in the fileName POST parameter.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2021-35395 Realtek · AP-Router SDK Added Nov 3, 2021

Realtek AP-Router SDK Buffer Overflow Vulnerability

Realtek AP-Router SDK HTTP web server boa contains a buffer overflow vulnerability due to unsafe copies of some overly long parameters submitted in the form that lead to denial-of-service (DoS).

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2017-16651 Roundcube · Roundcube Webmail Added Nov 3, 2021

Roundcube Webmail File Disclosure Vulnerability

Roundcube Webmail contains a file disclosure vulnerability caused by insufficient input validation in conjunction with file-based attachment plugins, which are used by default.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2020-11652 SaltStack · Salt Added Nov 3, 2021

SaltStack Salt Path Traversal Vulnerability

SaltStack Salt contains a path traversal vulnerability in the salt-master process ClearFuncs which allows directory access to authenticated users. Salt users who follow fundamental internet security guidelines and best practices are not affected by this vulnerability.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2020-11651 SaltStack · Salt Added Nov 3, 2021

SaltStack Salt Authentication Bypass Vulnerability

SaltStack Salt contains an authentication bypass vulnerability in the salt-master process ClearFuncs due to improperly validating method calls. The vulnerability allows a remote user to access some methods without authentication, which can be used to retrieve user tokens from the salt master and/or run commands on salt minions. Salt users who follow fundamental internet security guidelines and best practices are not affected by this vulnerability.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2020-16846 SaltStack · Salt Added Nov 3, 2021

SaltStack Salt Shell Injection Vulnerability

SaltStack Salt allows an unauthenticated user with network access to the Salt API to use shell injections to run code on the Salt API using the SSH client. This vulnerability affects any users running the Salt API.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2018-2380 SAP · Customer Relationship Management (CRM) Added Nov 3, 2021

SAP Customer Relationship Management (CRM) Path Traversal Vulnerability

SAP Customer Relationship Management (CRM) contains a path traversal vulnerability that allows an attacker to exploit insufficient validation of path information provided by users.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2010-5326 SAP · NetWeaver Added Nov 3, 2021

SAP NetWeaver Remote Code Execution Vulnerability

SAP NetWeaver Application Server Java Platforms Invoker Servlet does not require authentication, allowing for remote code execution via a HTTP or HTTPS request.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2016-9563 SAP · NetWeaver Added Nov 3, 2021

SAP NetWeaver XML External Entity (XXE) Vulnerability

SAP NetWeaver Application Server Java Platforms contains an unspecified vulnerability in BC-BMT-BPM-DSK which allows remote, authenticated users to conduct XML External Entity (XXE) attacks.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2020-6287 SAP · NetWeaver Added Nov 3, 2021

SAP NetWeaver Missing Authentication for Critical Function Vulnerability

SAP NetWeaver Application Server Java Platforms contains a missing authentication for critical function vulnerability allowing unauthenticated access to execute configuration tasks and create administrative users.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2020-6207 SAP · Solution Manager Added Nov 3, 2021

SAP Solution Manager Missing Authentication for Critical Function Vulnerability

SAP Solution Manager User Experience Monitoring contains a missing authentication for critical function vulnerability which results in complete compromise of all SMDAgents connected to the Solution Manager.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2016-3976 SAP · NetWeaver Added Nov 3, 2021

SAP NetWeaver Directory Traversal Vulnerability

SAP NetWeaver Application Server Java Platforms contains a directory traversal vulnerability via a ..\ (dot dot backslash) in the fileName parameter to CrashFileDownloadServlet. This allows remote attackers to read files.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2019-16256 SIMalliance · Toolbox Browser Added Nov 3, 2021

SIMalliance Toolbox Browser Command Injection Vulnerability

SIMalliance Toolbox Browser contains an command injection vulnerability that could allow remote attackers to retrieve location and IMEI information or execute a range of other attacks by modifying the attack message.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2020-10148 SolarWinds · Orion Added Nov 3, 2021

SolarWinds Orion Authentication Bypass Vulnerability

SolarWinds Orion API contains an authentication bypass vulnerability that could allow a remote attacker to execute API commands.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2021-35211 SolarWinds · Serv-U Added Nov 3, 2021

SolarWinds Serv-U Remote Code Execution Vulnerability

SolarWinds Serv-U contains an unspecified memory escape vulnerability which can allow for remote code execution.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2016-3643 SolarWinds · Virtualization Manager Added Nov 3, 2021

SolarWinds Virtualization Manager Privilege Escalation Vulnerability

SolarWinds Virtualization Manager allows for privilege escalation through leveraging a misconfiguration of sudo.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2020-10199 Sonatype · Nexus Repository Added Nov 3, 2021

Sonatype Nexus Repository Remote Code Execution Vulnerability

Sonatype Nexus Repository contains an unspecified vulnerability that allows for remote code execution.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2021-20021 SonicWall · SonicWall Email Security Added Nov 3, 2021

SonicWall Email Security Improper Privilege Management Vulnerability

SonicWall Email Security contains an improper privilege management vulnerability that allows an attacker to create an administrative account by sending a crafted HTTP request to the remote host. This vulnerability has known usage in a SonicWall Email Security exploit chain along with CVE-2021-20022 and CVE-2021-20023 to achieve privilege escalation.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2019-7481 SonicWall · SMA100 Added Nov 3, 2021

SonicWall SMA100 SQL Injection Vulnerability

SonicWall SMA100 contains a SQL injection vulnerability allowing an unauthenticated user to gain read-only access to unauthorized resources.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2021-20022 SonicWall · SonicWall Email Security Added Nov 3, 2021

SonicWall Email Security Unrestricted Upload of File Vulnerability

SonicWall Email Security contains an unrestricted upload of file with dangerous type vulnerability that allows a post-authenticated attacker to upload a file to the remote host. This vulnerability has known usage in a SonicWall Email Security exploit chain along with CVE-2021-20021 and CVE-2021-20023 to achieve privilege escalation.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2021-20023 SonicWall · SonicWall Email Security Added Nov 3, 2021

SonicWall Email Security Path Traversal Vulnerability

SonicWall Email Security contains a path traversal vulnerability that allows a post-authenticated attacker to read files on the remote host. This vulnerability has known usage in a SonicWall Email Security exploit chain along with CVE-2021-20021 and CVE-2021-20022 to achieve privilege escalation.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2021-20016 SonicWall · SSLVPN SMA100 Added Nov 3, 2021

SonicWall SSLVPN SMA100 SQL Injection Vulnerability

SonicWall SSLVPN SMA100 contains a SQL injection vulnerability that allows remote exploitation for credential access by an unauthenticated attacker.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed

Need help prioritizing these vulnerabilities?

ThreatGrid can assess your environment and map active CVEs to your monitored assets.