CISA known exploited vulnerabilities
Under attack. Patch these first.
Page 15 of 21
Alerts tracked
2627
Security flaws we track for Upstate SC businesses.
Known exploited
503
On CISA’s list of vulnerabilities attackers are actively using. Patch these first.
New exploited this month
43
Fresh additions to that CISA list since the first of the month.Feeds last synced Aug 20, 2026, 6:00 AM UTC.
Showing page 15 (24 alerts) of 503 known-exploited alerts.
QNAP NAS File Station Cross-Site Scripting Vulnerability
QNAP Network Attached Storage (NAS) is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2018-19943). A cross-site scripting vulnerability affecting QNAP NAS File Station could allow remote attackers to inject malicious code. CISA remediation due date: 2022-06-14. If you need help checking exposure, call (864) 335-9223.
Kaseya VSA SQL Injection Vulnerability
Kaseya Virtual System/Server Administrator (VSA) is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2017-18362). ConnectWise ManagedITSync integration for Kaseya VSA is vulnerable to unauthenticated remote commands that allow full direct access to the Kaseya VSA database. CISA remediation due date: 2022-06-14. If you need help checking exposure, call (864) 335-9223.
Microsoft Windows SMBv1 Information Disclosure Vulnerability
Microsoft SMBv1 server is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2017-0147). The SMBv1 server in Microsoft Windows allows remote attackers to obtain sensitive information from process memory via a crafted packet. CISA remediation due date: 2022-06-14. If you need help checking exposure, call (864) 335-9223.
Microsoft Internet Explorer and Edge Information Disclosure Vulnerability
Microsoft Internet Explorer and Edge is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2016-3351). An information disclosure vulnerability exists in the way that certain functions in Internet Explorer and Edge handle objects in memory. The vulnerability could allow an attacker to detect specific files on the user's computer. CISA remediation due date: 2022-06-14. If you need help checking exposure, call (864) 335-9223.
Microsoft Update Notification Manager Privilege Escalation Vulnerability
Microsoft Update Notification Manager is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2020-0638). Microsoft Update Notification Manager contains an unspecified vulnerability that allows for privilege escalation. CISA remediation due date: 2022-06-13. If you need help checking exposure, call (864) 335-9223.
Microsoft Windows AppX Deployment Extensions Privilege Escalation Vulnerability
Microsoft Windows is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2019-1385). A privilege escalation vulnerability exists when the Windows AppX Deployment Extensions improperly performs privilege management, resulting in access to system files. CISA remediation due date: 2022-06-13. If you need help checking exposure, call (864) 335-9223.
Microsoft Windows AppX Deployment Service Privilege Escalation Vulnerability
Microsoft Windows is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2019-1130). A privilege escalation vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard links. CISA remediation due date: 2022-06-13. If you need help checking exposure, call (864) 335-9223.
F5 BIG-IP Missing Authentication Vulnerability
F5 BIG-IP is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2022-1388). F5 BIG-IP contains a missing authentication in critical function vulnerability which can allow for remote code execution, creation or deletion of files, or disabling services. CISA remediation due date: 2022-05-31. If you need help checking exposure, call (864) 335-9223.
WSO2 Multiple Products Unrestrictive Upload of File Vulnerability
WSO2 Multiple Products is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2022-29464). Multiple WSO2 products allow for unrestricted file upload, resulting in remote code execution. CISA remediation due date: 2022-05-16. If you need help checking exposure, call (864) 335-9223.
Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) Vulnerability
Synacor Zimbra Collaboration Suite (ZCS) is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2018-6882). Synacor Zimbra Collaboration Suite (ZCS) contains a cross-site scripting vulnerability that might allow remote attackers to inject arbitrary web script or HTML. CISA remediation due date: 2022-05-10. If you need help checking exposure, call (864) 335-9223.
D-Link DNS-320 Remote Code Execution Vulnerability
D-Link DNS-320 Storage Device is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2019-16057). The login_mgr.cgi script in D-Link DNS-320 is vulnerable to remote code execution. CISA remediation due date: 2022-05-06. If you need help checking exposure, call (864) 335-9223.
VMware Workspace ONE Access and Identity Manager Server-Side Template Injection Vulnerability
VMware Workspace ONE Access and Identity Manager is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2022-22954). VMware Workspace ONE Access and Identity Manager allow for remote code execution due to server-side template injection. CISA remediation due date: 2022-05-05. If you need help checking exposure, call (864) 335-9223.
Microsoft Windows CLFS Driver Privilege Escalation Vulnerability
Microsoft Windows is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2022-24521). Microsoft Windows Common Log File System (CLFS) Driver contains an unspecified vulnerability that allows for privilege escalation. CISA remediation due date: 2022-05-04. If you need help checking exposure, call (864) 335-9223.
Drupal Core Remote Code Execution Vulnerability
Drupal Core is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2018-7602). A remote code execution vulnerability exists within multiple subsystems of Drupal that can allow attackers to exploit multiple attack vectors on a Drupal site. CISA remediation due date: 2022-05-04. If you need help checking exposure, call (864) 335-9223.
Kaseya VSA Remote Code Execution Vulnerability
Kaseya Virtual System/Server Administrator (VSA) is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2018-20753). Kaseya VSA RMM allows unprivileged remote attackers to execute PowerShell payloads on all managed devices. CISA remediation due date: 2022-05-04. If you need help checking exposure, call (864) 335-9223.
Microsoft Active Directory Domain Services Privilege Escalation Vulnerability
Microsoft Active Directory is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2021-42287). Microsoft Active Directory Domain Services contains an unspecified vulnerability that allows for privilege escalation. CISA remediation due date: 2022-05-02. If you need help checking exposure, call (864) 335-9223.
Microsoft Active Directory Domain Services Privilege Escalation Vulnerability
Microsoft Active Directory is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2021-42278). Microsoft Active Directory Domain Services contains an unspecified vulnerability that allows for privilege escalation. CISA remediation due date: 2022-05-02. If you need help checking exposure, call (864) 335-9223.
Microsoft SMBv1 Server Remote Code Execution Vulnerability
Microsoft SMBv1 server is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2017-0148). The SMBv1 server in Microsoft allows remote attackers to execute arbitrary code via crafted packets. CISA remediation due date: 2022-04-27. If you need help checking exposure, call (864) 335-9223.
QNAP NAS Improper Authorization Vulnerability
QNAP Network Attached Storage (NAS) is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2021-28799). QNAP NAS running HBS 3 contains an improper authorization vulnerability which can allow remote attackers to log in to a device. CISA remediation due date: 2022-04-21. If you need help checking exposure, call (864) 335-9223.
Dasan GPON Routers Command Injection Vulnerability
Dasan Gigabit Passive Optical Network (GPON) Routers is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2018-10562). Dasan GPON Routers contain an authentication bypass vulnerability. When combined with CVE-2018-10561, exploitation can allow an attacker to perform remote code execution. CISA remediation due date: 2022-04-21. If you need help checking exposure, call (864) 335-9223.
Microsoft Office Access Connectivity Engine Remote Code Execution Vulnerability
Microsoft Office is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2021-38646). Microsoft Office Access Connectivity Engine contains an unspecified vulnerability which can allow for remote code execution. CISA remediation due date: 2022-04-18. If you need help checking exposure, call (864) 335-9223.
Atlassian Confluence Server Pre-Authorization Arbitrary File Read Vulnerability
Atlassian Confluence Server is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2021-26085). Affected versions of Atlassian Confluence Server allow remote attackers to view restricted resources via a pre-authorization arbitrary file read vulnerability in the /s/ endpoint. CISA remediation due date: 2022-04-18. If you need help checking exposure, call (864) 335-9223.
SonicWall Secure Remote Access (SRA) SQL Injection Vulnerability
SonicWall Secure Remote Access (SRA) is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2021-20028). SonicWall Secure Remote Access (SRA) products contain an improper neutralization of a SQL Command leading to SQL injection. CISA remediation due date: 2022-04-18. If you need help checking exposure, call (864) 335-9223.
Microsoft Windows Privilege Escalation Vulnerability
Microsoft Windows is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2018-8440). An elevation of privilege vulnerability exists when Windows improperly handles calls to Advanced Local Procedure Call (ALPC). CISA remediation due date: 2022-04-18. If you need help checking exposure, call (864) 335-9223.