Skip to main content

Security Briefs

Page 10 of 21.

Alerts tracked

2625

Security flaws we track for Upstate SC businesses.

Known exploited

503

On CISA’s list of vulnerabilities attackers are actively using. Patch these first.

New exploited this month

43

Fresh additions to that CISA list since the first of the month.Feeds last synced Aug 19, 2026, 6:00 AM UTC.

Showing page 10 (24 alerts) of 503.

Actively exploited (KEV)Ransomware

CVE-2024-38094

Microsoft SharePoint Deserialization Vulnerability

Microsoft SharePoint is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2024-38094). Microsoft SharePoint contains a deserialization vulnerability that allows for remote code execution. CISA remediation due date: 2024-11-12. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2024-40711

Veeam Backup and Replication Deserialization Vulnerability

Veeam Backup & Replication is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2024-40711). Veeam Backup and Replication contains a deserialization vulnerability allowing an unauthenticated user to perform remote code execution. CISA remediation due date: 2024-11-07. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2024-9680

Mozilla Firefox Use-After-Free Vulnerability

Mozilla Firefox is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2024-9680). Mozilla Firefox and Firefox ESR contain a use-after-free vulnerability in Animation timelines that allows for code execution in the content process. CISA remediation due date: 2024-11-05. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2024-30088

Microsoft Windows Kernel TOCTOU Race Condition Vulnerability

Microsoft Windows is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2024-30088). Microsoft Windows Kernel contains a time-of-check to time-of-use (TOCTOU) race condition vulnerability that could allow for privilege escalation. CISA remediation due date: 2024-11-05. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2020-0618

Microsoft SQL Server Reporting Services Remote Code Execution Vulnerability

Microsoft SQL Server is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2020-0618). Microsoft SQL Server Reporting Services contains a deserialization vulnerability when handling page requests incorrectly. An authenticated attacker can exploit this vulnerability to execute code in the context of the Report Server service account. CISA remediation due date: 2024-10-09. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2024-6670

Progress WhatsUp Gold SQL Injection Vulnerability

Progress WhatsUp Gold is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2024-6670). Progress WhatsUp Gold contains a SQL injection vulnerability that allows an unauthenticated attacker to retrieve the user's encrypted password if the application is configured with only a single user. CISA remediation due date: 2024-10-07. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2024-40766

SonicWall SonicOS Improper Access Control Vulnerability

SonicWall SonicOS is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2024-40766). SonicWall SonicOS contains an improper access control vulnerability that could lead to unauthorized resource access and, under certain conditions, may cause the firewall to crash. CISA remediation due date: 2024-09-30. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2017-1000253

Linux Kernel PIE Stack Buffer Corruption Vulnerability

Linux Kernel is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2017-1000253). Linux kernel contains a position-independent executable (PIE) stack buffer corruption vulnerability in load_elf_ binary() that allows a local attacker to escalate privileges. CISA remediation due date: 2024-09-30. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2024-23897

Jenkins Command Line Interface (CLI) Path Traversal Vulnerability

Jenkins Jenkins Command Line Interface (CLI) is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2024-23897). Jenkins Command Line Interface (CLI) contains a path traversal vulnerability that allows attackers limited read access to certain files, which can lead to code execution. CISA remediation due date: 2024-09-09. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2024-37085

VMware ESXi Authentication Bypass Vulnerability

VMware ESXi is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2024-37085). VMware ESXi contains an authentication bypass vulnerability. A malicious actor with sufficient Active Directory (AD) permissions can gain full access to an ESXi host that was previously configured to use AD for user management by re-creating the configured AD group ('ESXi Admins' by default) after it was deleted from AD. CISA remediation due date: 2024-08-20. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2024-23692

Rejetto HTTP File Server Improper Neutralization of Special Elements Used in a Template Engine Vulnerability

Rejetto HTTP File Server is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2024-23692). Rejetto HTTP File Server contains an improper neutralization of special elements used in a template engine vulnerability. This allows a remote, unauthenticated attacker to execute commands on the affected system by sending a specially crafted HTTP request. CISA remediation due date: 2024-07-30. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2024-26169

Microsoft Windows Error Reporting Service Improper Privilege Management Vulnerability

Microsoft Windows is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2024-26169). Microsoft Windows Error Reporting Service contains an improper privilege management vulnerability that allows a local attacker with user permissions to gain SYSTEM privileges. CISA remediation due date: 2024-07-04. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2024-4577

PHP-CGI OS Command Injection Vulnerability

PHP Group PHP is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2024-4577). PHP, specifically Windows-based PHP used in CGI mode, contains an OS command injection vulnerability that allows for arbitrary code execution. This vulnerability is a patch bypass for CVE-2012-1823. CISA remediation due date: 2024-07-03. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2024-24919

Check Point Quantum Security Gateways Information Disclosure Vulnerability

Check Point Quantum Security Gateways is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2024-24919). Check Point Quantum Security Gateways contain an unspecified information disclosure vulnerability. The vulnerability potentially allows an attacker to access information on Gateways connected to the internet, with IPSec VPN, Remote Access VPN or Mobile Access enabled. This issue affects several product lines from Check Point, including CloudGuard Network, Quantum Scalable Chassis, Quantum Security Gateways, and Quantum Spark Appliances. CISA remediation due date: 2024-06-20. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2024-1086

Linux Kernel Use-After-Free Vulnerability

Linux Kernel is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2024-1086). Linux kernel contains a use-after-free vulnerability in the netfilter: nf_tables component that allows an attacker to achieve local privilege escalation. CISA remediation due date: 2024-06-20. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2023-43208

NextGen Healthcare Mirth Connect Deserialization of Untrusted Data Vulnerability

NextGen Healthcare Mirth Connect is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2023-43208). NextGen Healthcare Mirth Connect contains a deserialization of untrusted data vulnerability that allows for unauthenticated remote code execution via a specially crafted request. CISA remediation due date: 2024-06-10. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2024-30051

Microsoft DWM Core Library Privilege Escalation Vulnerability

Microsoft DWM Core Library is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2024-30051). Microsoft DWM Core Library contains a privilege escalation vulnerability that allows an attacker to gain SYSTEM privileges. CISA remediation due date: 2024-06-04. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2024-3400

Palo Alto Networks PAN-OS Command Injection Vulnerability

Palo Alto Networks PAN-OS is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2024-3400). Palo Alto Networks PAN-OS GlobalProtect feature contains a command injection vulnerability that allows an unauthenticated attacker to execute commands with root privileges on the firewall. CISA remediation due date: 2024-04-19. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2023-24955

Microsoft SharePoint Server Code Injection Vulnerability

Microsoft SharePoint Server is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2023-24955). Microsoft SharePoint Server contains a code injection vulnerability that allows an authenticated attacker with Site Owner privileges to execute code remotely. CISA remediation due date: 2024-04-16. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2023-48788

Fortinet FortiClient EMS SQL Injection Vulnerability

Fortinet FortiClient EMS is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2023-48788). Fortinet FortiClient EMS contains a SQL injection vulnerability that allows an unauthenticated attacker to execute commands as SYSTEM via specifically crafted requests. CISA remediation due date: 2024-04-15. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2021-44529

Ivanti Endpoint Manager Cloud Service Appliance (EPM CSA) Code Injection Vulnerability

Ivanti Endpoint Manager Cloud Service Appliance (EPM CSA) is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2021-44529). Ivanti Endpoint Manager Cloud Service Appliance (EPM CSA) contains a code injection vulnerability that allows an unauthenticated user to execute malicious code with limited permissions (nobody). CISA remediation due date: 2024-04-15. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2024-27198

JetBrains TeamCity Authentication Bypass Vulnerability

JetBrains TeamCity is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2024-27198). JetBrains TeamCity contains an authentication bypass vulnerability that allows an attacker to perform admin actions. CISA remediation due date: 2024-03-28. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2024-21338

Microsoft Windows Kernel Exposed IOCTL with Insufficient Access Control Vulnerability

Microsoft Windows is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2024-21338). Microsoft Windows Kernel contains an exposed IOCTL with insufficient access control vulnerability within the IOCTL (input and output control) dispatcher in appid.sys that allows a local attacker to achieve privilege escalation. CISA remediation due date: 2024-03-25. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2024-1709

ConnectWise ScreenConnect Authentication Bypass Vulnerability

ConnectWise ScreenConnect is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2024-1709). ConnectWise ScreenConnect contains an authentication bypass vulnerability that allows an attacker with network access to the management interface to create a new, administrator-level account on affected devices. CISA remediation due date: 2024-02-29. If you need help checking exposure, call (864) 335-9223.