Security Briefs
Page 106 of 111.
Alerts tracked
2651
Security flaws we track for Upstate SC businesses.
Known exploited
504
On CISA’s list of vulnerabilities attackers are actively using. Patch these first.
New exploited this month
60
Fresh additions to that CISA list since the first of the month.Feeds last synced Aug 24, 2026, 6:00 AM UTC.
Showing page 106 (24 alerts) of 2651.
Quest KACE System Management Appliance Remote Command Execution Vulnerability
Quest KACE System Management Appliance is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2018-11138). The '/common/download_agent_installer.php' script in the Quest KACE System Management Appliance is accessible by anonymous users and can be abused to perform remote code execution. CISA remediation due date: 2022-04-15. If you need help checking exposure, call (864) 335-9223.
Apache Tomcat on Windows Remote Code Execution Vulnerability
Apache Tomcat is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2017-12615). When running Apache Tomcat on Windows with HTTP PUTs enabled, it is possible to upload a JSP file to the server via a specially crafted request. This JSP could then be requested and any code it contained would be executed by the server. CISA remediation due date: 2022-04-15. If you need help checking exposure, call (864) 335-9223.
Microsoft Windows SMB Remote Code Execution Vulnerability
Microsoft Windows is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2017-0146). The SMBv1 server in Microsoft Windows allows remote attackers to perform remote code execution. CISA remediation due date: 2022-04-15. If you need help checking exposure, call (864) 335-9223.
Adobe ColdFusion Directory Traversal Vulnerability
Adobe ColdFusion is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2010-2861). A directory traversal vulnerability exists in the administrator console in Adobe ColdFusion which allows remote attackers to read arbitrary files. CISA remediation due date: 2022-04-15. If you need help checking exposure, call (864) 335-9223.
SonicWall SonicOS Buffer Overflow Vulnerability
SonicWall SonicOS is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2020-5135). A buffer overflow vulnerability in SonicOS allows a remote attacker to cause Denial of Service (DoS) and potentially execute arbitrary code by sending a malicious request to the firewall. CISA remediation due date: 2022-04-05. If you need help checking exposure, call (864) 335-9223.
Microsoft Windows Universal Plug and Play (UPnP) Service Privilege Escalation Vulnerability
Microsoft Windows is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2019-1405). A privilege escalation vulnerability exists when the Windows UPnP service improperly allows COM object creation. CISA remediation due date: 2022-04-05. If you need help checking exposure, call (864) 335-9223.
Microsoft Windows Privilege Escalation Vulnerability
Microsoft Windows is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2019-1322). A privilege escalation vulnerability exists when Windows improperly handles authentication requests. An attacker who successfully exploited this vulnerability could run processes in an elevated context. CISA remediation due date: 2022-04-05. If you need help checking exposure, call (864) 335-9223.
Microsoft Windows Error Reporting Manager Privilege Escalation Vulnerability
Microsoft Windows is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2019-1315). A privilege escalation vulnerability exists when Windows Error Reporting manager improperly handles hard links. An attacker who successfully exploited this vulnerability could overwrite a targeted file leading to an elevated status. CISA remediation due date: 2022-04-05. If you need help checking exposure, call (864) 335-9223.
Microsoft Windows AppX Deployment Server Privilege Escalation Vulnerability
Microsoft Windows is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2019-1253). A privilege escalation vulnerability exists when the Windows AppX Deployment Server improperly handles junctions. CISA remediation due date: 2022-04-05. If you need help checking exposure, call (864) 335-9223.
Microsoft Windows AppX Deployment Service (AppXSVC) Privilege Escalation Vulnerability
Microsoft Windows is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2019-1129). A privilege escalation vulnerability exists when Windows AppXSVC improperly handles hard links. An attacker who successfully exploited this vulnerability could run processes in an elevated context. CISA remediation due date: 2022-04-05. If you need help checking exposure, call (864) 335-9223.
Microsoft Task Scheduler Privilege Escalation Vulnerability
Microsoft Task Scheduler is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2019-1069). A privilege escalation vulnerability exists in the way the Task Scheduler Service validates certain file operations. CISA remediation due date: 2022-04-05. If you need help checking exposure, call (864) 335-9223.
Microsoft Windows AppX Deployment Service (AppXSVC) Privilege Escalation Vulnerability
Microsoft Windows is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2019-1064). A privilege escalation vulnerability exists when Windows AppXSVC improperly handles hard links. An attacker who successfully exploited this vulnerability could run processes in an elevated context. CISA remediation due date: 2022-04-05. If you need help checking exposure, call (864) 335-9223.
Microsoft Windows AppX Deployment Service (AppXSVC) Privilege Escalation Vulnerability
Microsoft Windows is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2019-0841). A privilege escalation vulnerability exists when Windows AppXSVC improperly handles hard links. An attacker who successfully exploited this vulnerability could run processes in an elevated context. CISA remediation due date: 2022-04-05. If you need help checking exposure, call (864) 335-9223.
Microsoft Windows Privilege Escalation Vulnerability
Microsoft Windows is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2019-0543). A privilege escalation vulnerability exists when Windows improperly handles authentication requests. An attacker who successfully exploited this vulnerability could run processes in an elevated context. CISA remediation due date: 2022-04-05. If you need help checking exposure, call (864) 335-9223.
Microsoft Win32k Privilege Escalation Vulnerability
Microsoft Win32k is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2018-8120). A privilege escalation vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory. CISA remediation due date: 2022-04-05. If you need help checking exposure, call (864) 335-9223.
Microsoft Windows Transaction Manager Privilege Escalation Vulnerability
Microsoft Windows is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2017-0101). A privilege escalation vulnerability exists when the Windows Transaction Manager improperly handles objects in memory. CISA remediation due date: 2022-04-05. If you need help checking exposure, call (864) 335-9223.
Microsoft Windows Kernel Privilege Escalation Vulnerability
Microsoft Windows is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2016-3309). A privilege escalation vulnerability exists when the Windows kernel fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. CISA remediation due date: 2022-04-05. If you need help checking exposure, call (864) 335-9223.
Microsoft Win32k Memory Corruption Vulnerability
Microsoft Win32k is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2015-2546). The kernel-mode driver in Microsoft Windows OS and Server allows local users to gain privileges via a crafted application. CISA remediation due date: 2022-04-05. If you need help checking exposure, call (864) 335-9223.
Adobe BlazeDS Information Disclosure Vulnerability
Adobe BlazeDS is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2009-3960). Adobe BlazeDS, which is utilized in LifeCycle and Coldfusion, contains a vulnerability that allows for information disclosure. CISA remediation due date: 2022-09-07. If you need help checking exposure, call (864) 335-9223.
Microsoft Windows Installer Privilege Escalation Vulnerability
Microsoft Windows is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2021-41379). Microsoft Windows Installer contains an unspecified vulnerability that allows for privilege escalation. CISA remediation due date: 2022-03-17. If you need help checking exposure, call (864) 335-9223.
Microsoft Exchange Server Privilege Escalation Vulnerability
Microsoft Exchange Server is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2018-8581). A privilege escalation vulnerability exists in Microsoft Exchange Server. An attacker who successfully exploited this vulnerability could attempt to impersonate any other user of the Exchange server. CISA remediation due date: 2022-03-17. If you need help checking exposure, call (864) 335-9223.
Adobe Flash Player Arbitrary Code Execution Vulnerability
Adobe Flash Player is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2016-1019). Adobe Flash Player allows remote attackers to cause a denial of service or possibly execute arbitrary code. CISA remediation due date: 2022-03-24. If you need help checking exposure, call (864) 335-9223.
Microsoft Windows Secondary Logon Service Privilege Escalation Vulnerability
Microsoft Windows is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2016-0099). A privilege escalation vulnerability exists in Microsoft Windows if the Windows Secondary Logon Service fails to properly manage request handles in memory. An attacker who successfully exploited this vulnerability could run arbitrary code as an administrator. CISA remediation due date: 2022-03-24. If you need help checking exposure, call (864) 335-9223.
Adobe Flash Player Arbitrary Code Execution Vulnerability
Adobe Flash Player is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2015-7645). Adobe Flash Player allows remote attackers to execute arbitrary code via a crafted SWF file. CISA remediation due date: 2022-03-24. If you need help checking exposure, call (864) 335-9223.