CISA known exploited vulnerabilities
Under attack. Patch these first.
Page 14 of 21
Alerts tracked
2627
Security flaws we track for Upstate SC businesses.
Known exploited
503
On CISA’s list of vulnerabilities attackers are actively using. Patch these first.
New exploited this month
43
Fresh additions to that CISA list since the first of the month.Feeds last synced Aug 20, 2026, 6:00 AM UTC.
Showing page 14 (24 alerts) of 503 known-exploited alerts.
dotCMS Unrestricted Upload of File Vulnerability
dotCMS dotCMS is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2022-26352). dotCMS ContentResource API contains an unrestricted upload of file with a dangerous type vulnerability that allows for directory traversal, in which the file is saved outside of the intended storage location. Exploitation allows for remote code execution. CISA remediation due date: 2022-09-15. If you need help checking exposure, call (864) 335-9223.
WebRTC Heap Buffer Overflow Vulnerability
WebRTC WebRTC is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2022-2294). WebRTC, an open-source project providing web browsers with real-time communication, contains a heap buffer overflow vulnerability that allows an attacker to perform shellcode execution. This vulnerability impacts web browsers using WebRTC including but not limited to Google Chrome. CISA remediation due date: 2022-09-15. If you need help checking exposure, call (864) 335-9223.
Synacor Zimbra Collaboration Suite (ZCS) Authentication Bypass Vulnerability
Synacor Zimbra Collaboration Suite (ZCS) is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2022-37042). Synacor Zimbra Collaboration Suite (ZCS) contains an authentication bypass vulnerability in MailboxImportServlet. This vulnerability was chained with CVE-2022-27925 which allows for unauthenticated remote code execution. CISA remediation due date: 2022-09-01. If you need help checking exposure, call (864) 335-9223.
Synacor Zimbra Collaboration Suite (ZCS) Arbitrary File Upload Vulnerability
Synacor Zimbra Collaboration Suite (ZCS) is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2022-27925). Synacor Zimbra Collaboration Suite (ZCS) contains flaw in the mboximport functionality, allowing an authenticated attacker to upload arbitrary files to perform remote code execution. This vulnerability was chained with CVE-2022-37042 which allows for unauthenticated remote code execution. CISA remediation due date: 2022-09-01. If you need help checking exposure, call (864) 335-9223.
RARLAB UnRAR Directory Traversal Vulnerability
RARLAB UnRAR is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2022-30333). RARLAB UnRAR on Linux and UNIX contains a directory traversal vulnerability, allowing an attacker to write to files during an extract (unpack) operation. CISA remediation due date: 2022-08-30. If you need help checking exposure, call (864) 335-9223.
Synacor Zimbra Collaboration Suite (ZCS) Command Injection Vulnerability
Synacor Zimbra Collaboration Suite (ZCS) is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2022-27924). Synacor Zimbra Collaboration Suite (ZCS) allows an attacker to inject memcache commands into a targeted instance which causes an overwrite of arbitrary cached entries. CISA remediation due date: 2022-08-25. If you need help checking exposure, call (864) 335-9223.
Mitel MiVoice Connect Data Validation Vulnerability
Mitel MiVoice Connect is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2022-29499). The Service Appliance component in Mitel MiVoice Connect allows remote code execution due to incorrect data validation. CISA remediation due date: 2022-07-18. If you need help checking exposure, call (864) 335-9223.
Red Hat Polkit Out-of-Bounds Read and Write Vulnerability
Red Hat Polkit is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2021-4034). The Red Hat polkit pkexec utility contains an out-of-bounds read and write vulnerability that allows for privilege escalation with administrative rights. CISA remediation due date: 2022-07-18. If you need help checking exposure, call (864) 335-9223.
Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability
Microsoft Windows is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2022-30190). A remote code execution vulnerability exists when MSDT is called using the URL protocol from a calling application such as Word. An attacker who successfully exploits this vulnerability can run code with the privileges of the calling application. CISA remediation due date: 2022-07-05. If you need help checking exposure, call (864) 335-9223.
QNAP Photo Station Path Traversal Vulnerability
QNAP Photo Station is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2019-7195). QNAP devices running Photo Station contain an external control of file name or path vulnerability allowing remote attackers to access or modify system files. CISA remediation due date: 2022-06-22. If you need help checking exposure, call (864) 335-9223.
QNAP Photo Station Path Traversal Vulnerability
QNAP Photo Station is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2019-7194). QNAP devices running Photo Station contain an external control of file name or path vulnerability allowing remote attackers to access or modify system files. CISA remediation due date: 2022-06-22. If you need help checking exposure, call (864) 335-9223.
QNAP QTS Improper Input Validation Vulnerability
QNAP QTS is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2019-7193). QNAP QTS contains an improper input validation vulnerability allowing remote attackers to inject code on the system. CISA remediation due date: 2022-06-22. If you need help checking exposure, call (864) 335-9223.
QNAP Photo Station Improper Access Control Vulnerability
QNAP Photo Station is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2019-7192). QNAP NAS devices running Photo Station contain an improper access control vulnerability allowing remote attackers to gain unauthorized access to the system. CISA remediation due date: 2022-06-22. If you need help checking exposure, call (864) 335-9223.
Atlassian Confluence Server and Data Center Remote Code Execution Vulnerability
Atlassian Confluence Server/Data Center is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2022-26134). Atlassian Confluence Server and Data Center contain a remote code execution vulnerability that allows for an unauthenticated attacker to perform remote code execution. CISA remediation due date: 2022-06-06. If you need help checking exposure, call (864) 335-9223.
Microsoft Silverlight Runtime Remote Code Execution Vulnerability
Microsoft Silverlight is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2016-0034). Microsoft Silverlight mishandles negative offsets during decoding, which allows attackers to execute remote code or cause a denial-of-service (DoS). CISA remediation due date: 2022-06-15. If you need help checking exposure, call (864) 335-9223.
IBM InfoSphere BigInsights Invalid Input Vulnerability
IBM InfoSphere BigInsights is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2013-3993). Certain APIs within BigInsights can take invalid input that might allow attackers unauthorized access to read, write, modify, or delete data. CISA remediation due date: 2022-06-15. If you need help checking exposure, call (864) 335-9223.
Oracle JRE Sandbox Bypass Vulnerability
Oracle Java Runtime Environment (JRE) is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2013-0431). Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle allows remote attackers to bypass the Java security sandbox. CISA remediation due date: 2022-06-15. If you need help checking exposure, call (864) 335-9223.
Oracle JRE Remote Code Execution Vulnerability
Oracle Java Runtime Environment (JRE) is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2013-0422). A vulnerability in the way Java restricts the permissions of Java applets could allow an attacker to execute commands on a vulnerable system. CISA remediation due date: 2022-06-15. If you need help checking exposure, call (864) 335-9223.
Microsoft Silverlight Double Dereference Vulnerability
Microsoft Silverlight is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2013-0074). Microsoft Silverlight does not properly validate pointers during HTML object rendering, which allows remote attackers to execute code via a crafted Silverlight application. CISA remediation due date: 2022-06-15. If you need help checking exposure, call (864) 335-9223.
Oracle Fusion Middleware Unspecified Vulnerability
Oracle Fusion Middleware is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2012-1710). Unspecified vulnerability in the Oracle WebCenter Forms Recognition component in Oracle Fusion Middleware allows remote attackers to affect confidentiality, integrity, and availability via Unknown vectors related to Designer. CISA remediation due date: 2022-06-15. If you need help checking exposure, call (864) 335-9223.
Red Hat JBoss Information Disclosure Vulnerability
Red Hat JBoss is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2010-1428). Unauthenticated access to the JBoss Application Server Web Console (/web-console) is blocked by default. However, it was found that this block was incomplete, and only blocked GET and POST HTTP verbs. A remote attacker could use this flaw to gain access to sensitive information. CISA remediation due date: 2022-06-15. If you need help checking exposure, call (864) 335-9223.
Red Hat JBoss Authentication Bypass Vulnerability
Red Hat JBoss is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2010-0738). The JMX-Console web application in JBossAs in Red Hat JBoss Enterprise Application Platform performs access control only for the GET and POST methods, which allows remote attackers to send requests to this application's GET handler by using a different method. CISA remediation due date: 2022-06-15. If you need help checking exposure, call (864) 335-9223.
QNAP NAS File Station Cross-Site Scripting Vulnerability
QNAP Network Attached Storage (NAS) is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2018-19953). A cross-site scripting vulnerability affecting QNAP NAS File Station could allow remote attackers to inject malicious code. CISA remediation due date: 2022-06-14. If you need help checking exposure, call (864) 335-9223.
QNAP NAS File Station Command Injection Vulnerability
QNAP Network Attached Storage (NAS) is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2018-19949). A command injection vulnerability affecting QNAP NAS File Station could allow remote attackers to run commands. CISA remediation due date: 2022-06-14. If you need help checking exposure, call (864) 335-9223.