Security Briefs
Page 104 of 111.
Alerts tracked
2651
Security flaws we track for Upstate SC businesses.
Known exploited
504
On CISA’s list of vulnerabilities attackers are actively using. Patch these first.
New exploited this month
60
Fresh additions to that CISA list since the first of the month.Feeds last synced Aug 24, 2026, 6:00 AM UTC.
Showing page 104 (24 alerts) of 2651.
Microsoft Silverlight Runtime Remote Code Execution Vulnerability
Microsoft Silverlight is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2016-0034). Microsoft Silverlight mishandles negative offsets during decoding, which allows attackers to execute remote code or cause a denial-of-service (DoS). CISA remediation due date: 2022-06-15. If you need help checking exposure, call (864) 335-9223.
IBM InfoSphere BigInsights Invalid Input Vulnerability
IBM InfoSphere BigInsights is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2013-3993). Certain APIs within BigInsights can take invalid input that might allow attackers unauthorized access to read, write, modify, or delete data. CISA remediation due date: 2022-06-15. If you need help checking exposure, call (864) 335-9223.
Oracle JRE Sandbox Bypass Vulnerability
Oracle Java Runtime Environment (JRE) is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2013-0431). Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle allows remote attackers to bypass the Java security sandbox. CISA remediation due date: 2022-06-15. If you need help checking exposure, call (864) 335-9223.
Oracle JRE Remote Code Execution Vulnerability
Oracle Java Runtime Environment (JRE) is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2013-0422). A vulnerability in the way Java restricts the permissions of Java applets could allow an attacker to execute commands on a vulnerable system. CISA remediation due date: 2022-06-15. If you need help checking exposure, call (864) 335-9223.
Microsoft Silverlight Double Dereference Vulnerability
Microsoft Silverlight is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2013-0074). Microsoft Silverlight does not properly validate pointers during HTML object rendering, which allows remote attackers to execute code via a crafted Silverlight application. CISA remediation due date: 2022-06-15. If you need help checking exposure, call (864) 335-9223.
Oracle Fusion Middleware Unspecified Vulnerability
Oracle Fusion Middleware is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2012-1710). Unspecified vulnerability in the Oracle WebCenter Forms Recognition component in Oracle Fusion Middleware allows remote attackers to affect confidentiality, integrity, and availability via Unknown vectors related to Designer. CISA remediation due date: 2022-06-15. If you need help checking exposure, call (864) 335-9223.
Red Hat JBoss Information Disclosure Vulnerability
Red Hat JBoss is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2010-1428). Unauthenticated access to the JBoss Application Server Web Console (/web-console) is blocked by default. However, it was found that this block was incomplete, and only blocked GET and POST HTTP verbs. A remote attacker could use this flaw to gain access to sensitive information. CISA remediation due date: 2022-06-15. If you need help checking exposure, call (864) 335-9223.
Red Hat JBoss Authentication Bypass Vulnerability
Red Hat JBoss is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2010-0738). The JMX-Console web application in JBossAs in Red Hat JBoss Enterprise Application Platform performs access control only for the GET and POST methods, which allows remote attackers to send requests to this application's GET handler by using a different method. CISA remediation due date: 2022-06-15. If you need help checking exposure, call (864) 335-9223.
QNAP NAS File Station Cross-Site Scripting Vulnerability
QNAP Network Attached Storage (NAS) is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2018-19953). A cross-site scripting vulnerability affecting QNAP NAS File Station could allow remote attackers to inject malicious code. CISA remediation due date: 2022-06-14. If you need help checking exposure, call (864) 335-9223.
QNAP NAS File Station Command Injection Vulnerability
QNAP Network Attached Storage (NAS) is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2018-19949). A command injection vulnerability affecting QNAP NAS File Station could allow remote attackers to run commands. CISA remediation due date: 2022-06-14. If you need help checking exposure, call (864) 335-9223.
QNAP NAS File Station Cross-Site Scripting Vulnerability
QNAP Network Attached Storage (NAS) is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2018-19943). A cross-site scripting vulnerability affecting QNAP NAS File Station could allow remote attackers to inject malicious code. CISA remediation due date: 2022-06-14. If you need help checking exposure, call (864) 335-9223.
Kaseya VSA SQL Injection Vulnerability
Kaseya Virtual System/Server Administrator (VSA) is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2017-18362). ConnectWise ManagedITSync integration for Kaseya VSA is vulnerable to unauthenticated remote commands that allow full direct access to the Kaseya VSA database. CISA remediation due date: 2022-06-14. If you need help checking exposure, call (864) 335-9223.
Microsoft Windows SMBv1 Information Disclosure Vulnerability
Microsoft SMBv1 server is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2017-0147). The SMBv1 server in Microsoft Windows allows remote attackers to obtain sensitive information from process memory via a crafted packet. CISA remediation due date: 2022-06-14. If you need help checking exposure, call (864) 335-9223.
Microsoft Internet Explorer and Edge Information Disclosure Vulnerability
Microsoft Internet Explorer and Edge is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2016-3351). An information disclosure vulnerability exists in the way that certain functions in Internet Explorer and Edge handle objects in memory. The vulnerability could allow an attacker to detect specific files on the user's computer. CISA remediation due date: 2022-06-14. If you need help checking exposure, call (864) 335-9223.
Microsoft Update Notification Manager Privilege Escalation Vulnerability
Microsoft Update Notification Manager is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2020-0638). Microsoft Update Notification Manager contains an unspecified vulnerability that allows for privilege escalation. CISA remediation due date: 2022-06-13. If you need help checking exposure, call (864) 335-9223.
Microsoft Windows AppX Deployment Extensions Privilege Escalation Vulnerability
Microsoft Windows is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2019-1385). A privilege escalation vulnerability exists when the Windows AppX Deployment Extensions improperly performs privilege management, resulting in access to system files. CISA remediation due date: 2022-06-13. If you need help checking exposure, call (864) 335-9223.
Microsoft Windows AppX Deployment Service Privilege Escalation Vulnerability
Microsoft Windows is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2019-1130). A privilege escalation vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard links. CISA remediation due date: 2022-06-13. If you need help checking exposure, call (864) 335-9223.
F5 BIG-IP Missing Authentication Vulnerability
F5 BIG-IP is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2022-1388). F5 BIG-IP contains a missing authentication in critical function vulnerability which can allow for remote code execution, creation or deletion of files, or disabling services. CISA remediation due date: 2022-05-31. If you need help checking exposure, call (864) 335-9223.
WSO2 Multiple Products Unrestrictive Upload of File Vulnerability
WSO2 Multiple Products is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2022-29464). Multiple WSO2 products allow for unrestricted file upload, resulting in remote code execution. CISA remediation due date: 2022-05-16. If you need help checking exposure, call (864) 335-9223.
Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) Vulnerability
Synacor Zimbra Collaboration Suite (ZCS) is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2018-6882). Synacor Zimbra Collaboration Suite (ZCS) contains a cross-site scripting vulnerability that might allow remote attackers to inject arbitrary web script or HTML. CISA remediation due date: 2022-05-10. If you need help checking exposure, call (864) 335-9223.
D-Link DNS-320 Remote Code Execution Vulnerability
D-Link DNS-320 Storage Device is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2019-16057). The login_mgr.cgi script in D-Link DNS-320 is vulnerable to remote code execution. CISA remediation due date: 2022-05-06. If you need help checking exposure, call (864) 335-9223.
VMware Workspace ONE Access and Identity Manager Server-Side Template Injection Vulnerability
VMware Workspace ONE Access and Identity Manager is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2022-22954). VMware Workspace ONE Access and Identity Manager allow for remote code execution due to server-side template injection. CISA remediation due date: 2022-05-05. If you need help checking exposure, call (864) 335-9223.
Microsoft Windows CLFS Driver Privilege Escalation Vulnerability
Microsoft Windows is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2022-24521). Microsoft Windows Common Log File System (CLFS) Driver contains an unspecified vulnerability that allows for privilege escalation. CISA remediation due date: 2022-05-04. If you need help checking exposure, call (864) 335-9223.
Drupal Core Remote Code Execution Vulnerability
Drupal Core is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2018-7602). A remote code execution vulnerability exists within multiple subsystems of Drupal that can allow attackers to exploit multiple attack vectors on a Drupal site. CISA remediation due date: 2022-05-04. If you need help checking exposure, call (864) 335-9223.