Security Briefs
Page 100 of 111.
Alerts tracked
2651
Security flaws we track for Upstate SC businesses.
Known exploited
504
On CISA’s list of vulnerabilities attackers are actively using. Patch these first.
New exploited this month
60
Fresh additions to that CISA list since the first of the month.Feeds last synced Aug 23, 2026, 6:00 AM UTC.
Showing page 100 (24 alerts) of 2651.
Linux Kernel Use-After-Free Vulnerability
Linux Kernel is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2024-1086). Linux kernel contains a use-after-free vulnerability in the netfilter: nf_tables component that allows an attacker to achieve local privilege escalation. CISA remediation due date: 2024-06-20. If you need help checking exposure, call (864) 335-9223.
NextGen Healthcare Mirth Connect Deserialization of Untrusted Data Vulnerability
NextGen Healthcare Mirth Connect is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2023-43208). NextGen Healthcare Mirth Connect contains a deserialization of untrusted data vulnerability that allows for unauthenticated remote code execution via a specially crafted request. CISA remediation due date: 2024-06-10. If you need help checking exposure, call (864) 335-9223.
Microsoft DWM Core Library Privilege Escalation Vulnerability
Microsoft DWM Core Library is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2024-30051). Microsoft DWM Core Library contains a privilege escalation vulnerability that allows an attacker to gain SYSTEM privileges. CISA remediation due date: 2024-06-04. If you need help checking exposure, call (864) 335-9223.
Palo Alto Networks PAN-OS Command Injection Vulnerability
Palo Alto Networks PAN-OS is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2024-3400). Palo Alto Networks PAN-OS GlobalProtect feature contains a command injection vulnerability that allows an unauthenticated attacker to execute commands with root privileges on the firewall. CISA remediation due date: 2024-04-19. If you need help checking exposure, call (864) 335-9223.
Microsoft SharePoint Server Code Injection Vulnerability
Microsoft SharePoint Server is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2023-24955). Microsoft SharePoint Server contains a code injection vulnerability that allows an authenticated attacker with Site Owner privileges to execute code remotely. CISA remediation due date: 2024-04-16. If you need help checking exposure, call (864) 335-9223.
Fortinet FortiClient EMS SQL Injection Vulnerability
Fortinet FortiClient EMS is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2023-48788). Fortinet FortiClient EMS contains a SQL injection vulnerability that allows an unauthenticated attacker to execute commands as SYSTEM via specifically crafted requests. CISA remediation due date: 2024-04-15. If you need help checking exposure, call (864) 335-9223.
Ivanti Endpoint Manager Cloud Service Appliance (EPM CSA) Code Injection Vulnerability
Ivanti Endpoint Manager Cloud Service Appliance (EPM CSA) is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2021-44529). Ivanti Endpoint Manager Cloud Service Appliance (EPM CSA) contains a code injection vulnerability that allows an unauthenticated user to execute malicious code with limited permissions (nobody). CISA remediation due date: 2024-04-15. If you need help checking exposure, call (864) 335-9223.
JetBrains TeamCity Authentication Bypass Vulnerability
JetBrains TeamCity is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2024-27198). JetBrains TeamCity contains an authentication bypass vulnerability that allows an attacker to perform admin actions. CISA remediation due date: 2024-03-28. If you need help checking exposure, call (864) 335-9223.
Microsoft Windows Kernel Exposed IOCTL with Insufficient Access Control Vulnerability
Microsoft Windows is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2024-21338). Microsoft Windows Kernel contains an exposed IOCTL with insufficient access control vulnerability within the IOCTL (input and output control) dispatcher in appid.sys that allows a local attacker to achieve privilege escalation. CISA remediation due date: 2024-03-25. If you need help checking exposure, call (864) 335-9223.
ConnectWise ScreenConnect Authentication Bypass Vulnerability
ConnectWise ScreenConnect is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2024-1709). ConnectWise ScreenConnect contains an authentication bypass vulnerability that allows an attacker with network access to the management interface to create a new, administrator-level account on affected devices. CISA remediation due date: 2024-02-29. If you need help checking exposure, call (864) 335-9223.
Cisco ASA and FTD Information Disclosure Vulnerability
Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2020-3259). Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) contain an information disclosure vulnerability. An attacker could retrieve memory contents on an affected device, which could lead to the disclosure of confidential information due to a buffer tracking issue when the software parses invalid URLs that are requested from the web services interface. This vulnerability affects only specific AnyConnect and WebVPN configurations. CISA remediation due date: 2024-03-07. If you need help checking exposure, call (864) 335-9223.
Microsoft Windows Internet Shortcut Files Security Feature Bypass Vulnerability
Microsoft Windows is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2024-21412). Microsoft Windows Internet Shortcut Files contains an unspecified vulnerability that allows for a security feature bypass. CISA remediation due date: 2024-03-05. If you need help checking exposure, call (864) 335-9223.
Fortinet FortiOS Out-of-Bound Write Vulnerability
Fortinet FortiOS is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2024-21762). Fortinet FortiOS contains an out-of-bound write vulnerability that allows a remote unauthenticated attacker to execute code or commands via specially crafted HTTP requests. CISA remediation due date: 2024-02-16. If you need help checking exposure, call (864) 335-9223.
Ivanti Connect Secure, Policy Secure, and Neurons Server-Side Request Forgery (SSRF) Vulnerability
Ivanti Connect Secure, Policy Secure, and Neurons is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2024-21893). Ivanti Connect Secure (ICS, formerly known as Pulse Connect Secure), Ivanti Policy Secure, and Ivanti Neurons contain a server-side request forgery (SSRF) vulnerability in the SAML component that allows an attacker to access certain restricted resources without authentication. CISA remediation due date: 2024-02-02. If you need help checking exposure, call (864) 335-9223.
Atlassian Confluence Data Center and Server Template Injection Vulnerability
Atlassian Confluence Data Center and Server is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2023-22527). Atlassian Confluence Data Center and Server contain an unauthenticated OGNL template injection vulnerability that can lead to remote code execution. CISA remediation due date: 2024-02-14. If you need help checking exposure, call (864) 335-9223.
Ivanti Endpoint Manager Mobile (EPMM) and MobileIron Core Authentication Bypass Vulnerability
Ivanti Endpoint Manager Mobile (EPMM) and MobileIron Core is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2023-35082). Ivanti Endpoint Manager Mobile (EPMM) and MobileIron Core contain an authentication bypass vulnerability that allows unauthorized users to access restricted functionality or resources of the application. CISA remediation due date: 2024-02-08. If you need help checking exposure, call (864) 335-9223.
Ivanti Connect Secure and Policy Secure Command Injection Vulnerability
Ivanti Connect Secure and Policy Secure is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2024-21887). Ivanti Connect Secure (ICS, formerly known as Pulse Connect Secure) and Ivanti Policy Secure contain a command injection vulnerability in the web components of these products, which can allow an authenticated administrator to send crafted requests to execute code on affected appliances. This vulnerability can be leveraged in conjunction with CVE-2023-46805, an authenticated bypass issue. CISA remediation due date: 2024-01-22. If you need help checking exposure, call (864) 335-9223.
Ivanti Connect Secure and Policy Secure Authentication Bypass Vulnerability
Ivanti Connect Secure and Policy Secure is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2023-46805). Ivanti Connect Secure (ICS, formerly known as Pulse Connect Secure) and Ivanti Policy Secure gateways contain an authentication bypass vulnerability in the web component that allows an attacker to access restricted resources by bypassing control checks. This vulnerability can be leveraged in conjunction with CVE-2024-21887, a command injection vulnerability. CISA remediation due date: 2024-01-22. If you need help checking exposure, call (864) 335-9223.
Microsoft SharePoint Server Privilege Escalation Vulnerability
Microsoft SharePoint Server is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2023-29357). Microsoft SharePoint Server contains an unspecified vulnerability that allows an unauthenticated attacker, who has gained access to spoofed JWT authentication tokens, to use them for executing a network attack. This attack bypasses authentication, enabling the attacker to gain administrator privileges. CISA remediation due date: 2024-01-31. If you need help checking exposure, call (864) 335-9223.
Adobe ColdFusion Deserialization of Untrusted Data Vulnerability
Adobe ColdFusion is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2023-38203). Adobe ColdFusion contains a deserialization of untrusted data vulnerability that allows for code execution. CISA remediation due date: 2024-01-29. If you need help checking exposure, call (864) 335-9223.
Adobe ColdFusion Deserialization of Untrusted Data Vulnerability
Adobe ColdFusion is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2023-29300). Adobe ColdFusion contains a deserialization of untrusted data vulnerability that allows for code execution. CISA remediation due date: 2024-01-29. If you need help checking exposure, call (864) 335-9223.
Qlik Sense Path Traversal Vulnerability
Qlik Sense is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2023-41266). Qlik Sense contains a path traversal vulnerability that allows a remote, unauthenticated attacker to create an anonymous session by sending maliciously crafted HTTP requests. This anonymous session could allow the attacker to send further requests to unauthorized endpoints. CISA remediation due date: 2023-12-28. If you need help checking exposure, call (864) 335-9223.
Qlik Sense HTTP Tunneling Vulnerability
Qlik Sense is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2023-41265). Qlik Sense contains an HTTP tunneling vulnerability that allows an attacker to escalate privileges and execute HTTP requests on the backend server hosting the software. CISA remediation due date: 2023-12-28. If you need help checking exposure, call (864) 335-9223.
SysAid Server Path Traversal Vulnerability
SysAid SysAid Server is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2023-47246). SysAid Server (on-premises version) contains a path traversal vulnerability that leads to code execution. CISA remediation due date: 2023-12-04. If you need help checking exposure, call (864) 335-9223.