Skip to main content

Security Briefs

Page 104 of 111.

Alerts tracked

2651

Security flaws we track for Upstate SC businesses.

Known exploited

504

On CISA’s list of vulnerabilities attackers are actively using. Patch these first.

New exploited this month

60

Fresh additions to that CISA list since the first of the month.Feeds last synced Aug 24, 2026, 6:00 AM UTC.

Showing page 104 (24 alerts) of 2651.

Actively exploited (KEV)Ransomware

CVE-2016-0034

Microsoft Silverlight Runtime Remote Code Execution Vulnerability

Microsoft Silverlight is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2016-0034). Microsoft Silverlight mishandles negative offsets during decoding, which allows attackers to execute remote code or cause a denial-of-service (DoS). CISA remediation due date: 2022-06-15. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2013-3993

IBM InfoSphere BigInsights Invalid Input Vulnerability

IBM InfoSphere BigInsights is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2013-3993). Certain APIs within BigInsights can take invalid input that might allow attackers unauthorized access to read, write, modify, or delete data. CISA remediation due date: 2022-06-15. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2013-0431

Oracle JRE Sandbox Bypass Vulnerability

Oracle Java Runtime Environment (JRE) is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2013-0431). Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle allows remote attackers to bypass the Java security sandbox. CISA remediation due date: 2022-06-15. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2013-0422

Oracle JRE Remote Code Execution Vulnerability

Oracle Java Runtime Environment (JRE) is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2013-0422). A vulnerability in the way Java restricts the permissions of Java applets could allow an attacker to execute commands on a vulnerable system. CISA remediation due date: 2022-06-15. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2013-0074

Microsoft Silverlight Double Dereference Vulnerability

Microsoft Silverlight is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2013-0074). Microsoft Silverlight does not properly validate pointers during HTML object rendering, which allows remote attackers to execute code via a crafted Silverlight application. CISA remediation due date: 2022-06-15. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2012-1710

Oracle Fusion Middleware Unspecified Vulnerability

Oracle Fusion Middleware is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2012-1710). Unspecified vulnerability in the Oracle WebCenter Forms Recognition component in Oracle Fusion Middleware allows remote attackers to affect confidentiality, integrity, and availability via Unknown vectors related to Designer. CISA remediation due date: 2022-06-15. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2010-1428

Red Hat JBoss Information Disclosure Vulnerability

Red Hat JBoss is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2010-1428). Unauthenticated access to the JBoss Application Server Web Console (/web-console) is blocked by default. However, it was found that this block was incomplete, and only blocked GET and POST HTTP verbs. A remote attacker could use this flaw to gain access to sensitive information. CISA remediation due date: 2022-06-15. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2010-0738

Red Hat JBoss Authentication Bypass Vulnerability

Red Hat JBoss is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2010-0738). The JMX-Console web application in JBossAs in Red Hat JBoss Enterprise Application Platform performs access control only for the GET and POST methods, which allows remote attackers to send requests to this application's GET handler by using a different method. CISA remediation due date: 2022-06-15. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2018-19953

QNAP NAS File Station Cross-Site Scripting Vulnerability

QNAP Network Attached Storage (NAS) is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2018-19953). A cross-site scripting vulnerability affecting QNAP NAS File Station could allow remote attackers to inject malicious code. CISA remediation due date: 2022-06-14. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2018-19949

QNAP NAS File Station Command Injection Vulnerability

QNAP Network Attached Storage (NAS) is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2018-19949). A command injection vulnerability affecting QNAP NAS File Station could allow remote attackers to run commands. CISA remediation due date: 2022-06-14. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2018-19943

QNAP NAS File Station Cross-Site Scripting Vulnerability

QNAP Network Attached Storage (NAS) is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2018-19943). A cross-site scripting vulnerability affecting QNAP NAS File Station could allow remote attackers to inject malicious code. CISA remediation due date: 2022-06-14. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2017-18362

Kaseya VSA SQL Injection Vulnerability

Kaseya Virtual System/Server Administrator (VSA) is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2017-18362). ConnectWise ManagedITSync integration for Kaseya VSA is vulnerable to unauthenticated remote commands that allow full direct access to the Kaseya VSA database. CISA remediation due date: 2022-06-14. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2017-0147

Microsoft Windows SMBv1 Information Disclosure Vulnerability

Microsoft SMBv1 server is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2017-0147). The SMBv1 server in Microsoft Windows allows remote attackers to obtain sensitive information from process memory via a crafted packet. CISA remediation due date: 2022-06-14. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2016-3351

Microsoft Internet Explorer and Edge Information Disclosure Vulnerability

Microsoft Internet Explorer and Edge is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2016-3351). An information disclosure vulnerability exists in the way that certain functions in Internet Explorer and Edge handle objects in memory. The vulnerability could allow an attacker to detect specific files on the user's computer. CISA remediation due date: 2022-06-14. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2020-0638

Microsoft Update Notification Manager Privilege Escalation Vulnerability

Microsoft Update Notification Manager is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2020-0638). Microsoft Update Notification Manager contains an unspecified vulnerability that allows for privilege escalation. CISA remediation due date: 2022-06-13. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2019-1385

Microsoft Windows AppX Deployment Extensions Privilege Escalation Vulnerability

Microsoft Windows is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2019-1385). A privilege escalation vulnerability exists when the Windows AppX Deployment Extensions improperly performs privilege management, resulting in access to system files. CISA remediation due date: 2022-06-13. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2019-1130

Microsoft Windows AppX Deployment Service Privilege Escalation Vulnerability

Microsoft Windows is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2019-1130). A privilege escalation vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard links. CISA remediation due date: 2022-06-13. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2022-1388

F5 BIG-IP Missing Authentication Vulnerability

F5 BIG-IP is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2022-1388). F5 BIG-IP contains a missing authentication in critical function vulnerability which can allow for remote code execution, creation or deletion of files, or disabling services. CISA remediation due date: 2022-05-31. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2022-29464

WSO2 Multiple Products Unrestrictive Upload of File Vulnerability

WSO2 Multiple Products is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2022-29464). Multiple WSO2 products allow for unrestricted file upload, resulting in remote code execution. CISA remediation due date: 2022-05-16. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2018-6882

Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) Vulnerability

Synacor Zimbra Collaboration Suite (ZCS) is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2018-6882). Synacor Zimbra Collaboration Suite (ZCS) contains a cross-site scripting vulnerability that might allow remote attackers to inject arbitrary web script or HTML. CISA remediation due date: 2022-05-10. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2019-16057

D-Link DNS-320 Remote Code Execution Vulnerability

D-Link DNS-320 Storage Device is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2019-16057). The login_mgr.cgi script in D-Link DNS-320 is vulnerable to remote code execution. CISA remediation due date: 2022-05-06. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2022-22954

VMware Workspace ONE Access and Identity Manager Server-Side Template Injection Vulnerability

VMware Workspace ONE Access and Identity Manager is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2022-22954). VMware Workspace ONE Access and Identity Manager allow for remote code execution due to server-side template injection. CISA remediation due date: 2022-05-05. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2022-24521

Microsoft Windows CLFS Driver Privilege Escalation Vulnerability

Microsoft Windows is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2022-24521). Microsoft Windows Common Log File System (CLFS) Driver contains an unspecified vulnerability that allows for privilege escalation. CISA remediation due date: 2022-05-04. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2018-7602

Drupal Core Remote Code Execution Vulnerability

Drupal Core is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2018-7602). A remote code execution vulnerability exists within multiple subsystems of Drupal that can allow attackers to exploit multiple attack vectors on a Drupal site. CISA remediation due date: 2022-05-04. If you need help checking exposure, call (864) 335-9223.