Skip to main content

CISA known exploited vulnerabilities

Under attack. Patch these first.

Page 19 of 23

Alerts tracked

3939

Security flaws we track for Upstate SC businesses.

Known exploited

545

On CISA’s list of vulnerabilities attackers are actively using. Patch these first.

New exploited this month

2

Fresh additions to that CISA list since the first of the month.Feeds last synced Oct 6, 2026, 6:01 AM UTC.

Showing page 19 (24 alerts) of 545 known-exploited alerts.

Actively exploited (KEV)Ransomware

CVE-2016-4117

Adobe Flash Player Arbitrary Code Execution Vulnerability

Adobe Flash Player is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2016-4117). An access of resource using incompatible type vulnerability exists within Adobe Flash Player that allows an attacker to perform remote code execution. CISA remediation due date: 2022-03-24. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2016-1019

Adobe Flash Player Arbitrary Code Execution Vulnerability

Adobe Flash Player is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2016-1019). Adobe Flash Player allows remote attackers to cause a denial of service or possibly execute arbitrary code. CISA remediation due date: 2022-03-24. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2016-0099

Microsoft Windows Secondary Logon Service Privilege Escalation Vulnerability

Microsoft Windows is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2016-0099). A privilege escalation vulnerability exists in Microsoft Windows if the Windows Secondary Logon Service fails to properly manage request handles in memory. An attacker who successfully exploited this vulnerability could run arbitrary code as an administrator. CISA remediation due date: 2022-03-24. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2015-7645

Adobe Flash Player Arbitrary Code Execution Vulnerability

Adobe Flash Player is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2015-7645). Adobe Flash Player allows remote attackers to execute arbitrary code via a crafted SWF file. CISA remediation due date: 2022-03-24. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2015-1701

Microsoft Win32k Privilege Escalation Vulnerability

Microsoft Win32k is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2015-1701). An unspecified vulnerability exists in the Win32k.sys kernel-mode driver in Microsoft Windows Server that allows a local attacker to execute arbitrary code with elevated privileges. CISA remediation due date: 2022-03-24. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2012-4681

Oracle Java SE Runtime Environment (JRE) Arbitrary Code Execution Vulnerability

Oracle Java SE is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2012-4681). The Java Runtime Environment (JRE) component in Oracle Java SE allow for remote code execution. CISA remediation due date: 2022-03-24. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2012-1723

Oracle Java SE Runtime Environment (JRE) Arbitrary Code Execution Vulnerability

Oracle Java SE is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2012-1723). Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE allows remote attackers to affect confidentiality, integrity, and availability via Unknown vectors related to Hotspot. CISA remediation due date: 2022-03-24. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2012-0507

Oracle Java SE Runtime Environment (JRE) Arbitrary Code Execution Vulnerability

Oracle Java SE is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2012-0507). An incorrect type vulnerability exists in the Concurrency component of Oracle's Java Runtime Environment allows an attacker to remotely execute arbitrary code. CISA remediation due date: 2022-03-24. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2010-0188

Adobe Reader and Acrobat Arbitrary Code Execution Vulnerability

Adobe Reader and Acrobat is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2010-0188). Unspecified vulnerability in Adobe Reader and Acrobat allows attackers to cause a denial of service or possibly execute arbitrary code. CISA remediation due date: 2022-03-24. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2008-2992

Adobe Reader and Acrobat Input Validation Vulnerability

Adobe Acrobat and Reader is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2008-2992). Adobe Acrobat and Reader contain an input validation issue in a JavaScript method that could potentially lead to remote code execution. CISA remediation due date: 2022-03-24. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2022-24682

Synacor Zimbra Collaborate Suite (ZCS) Cross-Site Scripting Vulnerability

Synacor Zimbra Collaborate Suite (ZCS) is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2022-24682). Synacor Zimbra Collaboration Suite (ZCS) contains a cross-site scripting (XSS) vulnerability in the Calendar feature that allows an attacker to execute arbitrary code. CISA remediation due date: 2022-03-11. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2019-0752

Microsoft Internet Explorer Type Confusion Vulnerability

Microsoft Internet Explorer is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2019-0752). A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer CISA remediation due date: 2022-08-15. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2018-8174

Microsoft Windows VBScript Engine Out-of-Bounds Write Vulnerability

Microsoft Windows is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2018-8174). A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows VBScript Engine Remote Code Execution" CISA remediation due date: 2022-08-15. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2018-20250

WinRAR Absolute Path Traversal Vulnerability

RARLAB WinRAR is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2018-20250). WinRAR Absolute Path Traversal vulnerability leads to Remote Code Execution CISA remediation due date: 2022-08-15. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2018-15982

Adobe Flash Player Use-After-Free Vulnerability

Adobe Flash Player is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2018-15982). Adobe Flash Player com.adobe.tvsdk.mediacore.metadata Use After Free Vulnerability CISA remediation due date: 2022-08-15. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2020-0796

Microsoft SMBv3 Remote Code Execution Vulnerability

Microsoft SMBv3 is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2020-0796). A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol handles certain requests. An attacker who successfully exploited the vulnerability could gain the ability to execute code on the target server or client. CISA remediation due date: 2022-08-10. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2017-10271

Oracle Corporation WebLogic Server Remote Code Execution Vulnerability

Oracle WebLogic Server is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2017-10271). Oracle Corporation WebLogic Server contains a vulnerability that allows for remote code execution. CISA remediation due date: 2022-08-10. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2017-0145

Microsoft SMBv1 Remote Code Execution Vulnerability

Microsoft SMBv1 is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2017-0145). The SMBv1 server in multiple Microsoft Windows versions allows remote attackers to execute arbitrary code via crafted packets. CISA remediation due date: 2022-08-10. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2017-0144

Microsoft SMBv1 Remote Code Execution Vulnerability

Microsoft SMBv1 is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2017-0144). The SMBv1 server in multiple Microsoft Windows versions allows remote attackers to execute arbitrary code via crafted packets. CISA remediation due date: 2022-08-10. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2022-21882

Microsoft Win32k Privilege Escalation Vulnerability

Microsoft Win32k is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2022-21882). Microsoft Win32k contains an unspecified vulnerability that allows for privilege escalation. CISA remediation due date: 2022-02-18. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2021-20038

SonicWall SMA 100 Appliances Stack-Based Buffer Overflow Vulnerability

SonicWall SMA 100 Appliances is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2021-20038). SonicWall SMA 100 devies are vulnerable to an unauthenticated stack-based buffer overflow vulnerability where exploitation can result in code execution. CISA remediation due date: 2022-02-11. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2020-0787

Microsoft Windows Background Intelligent Transfer Service (BITS) Improper Privilege Management Vulnerability

Microsoft Windows is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2020-0787). Microsoft Windows BITS is vulnerable to to a privilege elevation vulnerability if it improperly handles symbolic links. An actor can exploit this vulnerability to execute arbitrary code with system-level privileges. CISA remediation due date: 2022-07-28. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2018-8453

Microsoft Win32k Privilege Escalation Vulnerability

Microsoft Win32k is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2018-8453). Microsoft Windows Win32k contains a vulnerability that allows an attacker to escalate privileges. CISA remediation due date: 2022-07-21. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2021-21975

VMware Server Side Request Forgery in vRealize Operations Manager API vulnerability

VMware vRealize Operations Manager API is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2021-21975). Server Side Request Forgery (SSRF) in vRealize Operations Manager API prior to 8.4 may allow a malicious actor with network access to the vRealize Operations Manager API to perform a SSRF attack to steal administrative credentials. CISA remediation due date: 2022-02-01. If you need help checking exposure, call (864) 335-9223.