Skip to main content

Security Briefs

Page 110 of 111.

Alerts tracked

2651

Security flaws we track for Upstate SC businesses.

Known exploited

504

On CISA’s list of vulnerabilities attackers are actively using. Patch these first.

New exploited this month

60

Fresh additions to that CISA list since the first of the month.Feeds last synced Aug 24, 2026, 6:00 AM UTC.

Showing page 110 (24 alerts) of 2651.

Actively exploited (KEV)Ransomware

CVE-2020-12812

Fortinet FortiOS SSL VPN Improper Authentication Vulnerability

Fortinet FortiOS is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2020-12812). Fortinet FortiOS SSL VPN contains an improper authentication vulnerability that may allow a user to login successfully without being prompted for the second factor of authentication (FortiToken) if they change the case in their username. CISA remediation due date: 2022-05-03. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2020-12271

Sophos SFOS SQL Injection Vulnerability

Sophos SFOS is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2020-12271). Sophos Firewall operating system (SFOS) firmware contains a SQL injection vulnerability when configured with either the administration (HTTPS) service or the User Portal is exposed on the WAN zone. Successful exploitation may cause remote code execution to exfiltrate usernames and hashed passwords for the local device admin(s), portal admins, and user accounts used for remote access (but not external Active Directory or LDAP passwords). CISA remediation due date: 2022-05-03. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2020-0968

Microsoft Internet Explorer Scripting Engine Memory Corruption Vulnerability

Microsoft Internet Explorer is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2020-0968). Microsoft Internet Explorer contains a memory corruption vulnerability due to how the Scripting Engine handles objects in memory, leading to remote code execution. CISA remediation due date: 2022-05-03. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2020-0878

Microsoft Edge and Internet Explorer Memory Corruption Vulnerability

Microsoft Edge and Internet Explorer is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2020-0878). Microsoft Edge and Internet Explorer contain a memory corruption vulnerability that allows attackers to execute code in the context of the current user. CISA remediation due date: 2022-05-03. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2020-0688

Microsoft Exchange Server Validation Key Remote Code Execution Vulnerability

Microsoft Exchange Server is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2020-0688). Microsoft Exchange Server Validation Key fails to properly create unique keys at install time, allowing for remote code execution. CISA remediation due date: 2022-05-03. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2019-7481

SonicWall SMA100 SQL Injection Vulnerability

SonicWall SMA100 is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2019-7481). SonicWall SMA100 contains a SQL injection vulnerability allowing an unauthenticated user to gain read-only access to unauthorized resources. CISA remediation due date: 2022-05-03. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2019-5591

Fortinet FortiOS Default Configuration Vulnerability

Fortinet FortiOS is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2019-5591). Fortinet FortiOS contains a default configuration vulnerability that may allow an unauthenticated attacker on the same subnet to intercept sensitive information by impersonating the Lightweight Directory Access Protocol (LDAP) server. CISA remediation due date: 2022-05-03. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2019-5544

VMware ESXi and Horizon DaaS OpenSLP Heap-Based Buffer Overflow Vulnerability

VMware VMware ESXi and Horizon DaaS is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2019-5544). VMware ESXi and Horizon Desktop as a Service (DaaS) OpenSLP contains a heap-based buffer overflow vulnerability that allows an attacker with network access to port 427 to overwrite the heap of the OpenSLP service to perform remote code execution. CISA remediation due date: 2022-05-03. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2019-3396

Atlassian Confluence Server and Data Center Server-Side Template Injection Vulnerability

Atlassian Confluence Server and Data Server is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2019-3396). Atlassian Confluence Server and Data Center contain a server-side template injection vulnerability that may allow an attacker to achieve path traversal and remote code execution. CISA remediation due date: 2022-05-03. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2019-19781

Citrix ADC, Gateway, and SD-WAN WANOP Appliance Code Execution Vulnerability

Citrix Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2019-19781). Citrix ADC, Citrix Gateway, and multiple Citrix SD-WAN WANOP appliance models contain an unspecified vulnerability that could allow an unauthenticated attacker to perform code execution. CISA remediation due date: 2022-05-03. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2019-18935

Progress Telerik UI for ASP.NET AJAX Deserialization of Untrusted Data Vulnerability

Progress Telerik UI for ASP.NET AJAX is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2019-18935). Progress Telerik UI for ASP.NET AJAX contains a deserialization of untrusted data vulnerability through RadAsyncUpload which leads to code execution on the server in the context of the w3wp.exe process. CISA remediation due date: 2022-05-03. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2019-1367

Microsoft Internet Explorer Scripting Engine Memory Corruption Vulnerability

Microsoft Internet Explorer is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2019-1367). Microsoft Internet Explorer contains a memory corruption vulnerability in how the scripting engine handles objects in memory. Successful exploitation allows for remote code execution in the context of the current user. CISA remediation due date: 2022-05-03. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2019-13608

Citrix StoreFront Server XML External Entity (XXE) Processing Vulnerability

Citrix StoreFront Server is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2019-13608). Citrix StoreFront Server contains an XML External Entity (XXE) processing vulnerability that may allow an unauthenticated attacker to retrieve potentially sensitive information. CISA remediation due date: 2022-05-03. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2019-1215

Microsoft Windows Privilege Escalation Vulnerability

Microsoft Windows is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2019-1215). Microsoft Windows contains an unspecified vulnerability due to the way ws2ifsl.sys (Winsock) handles objects in memory, allowing for privilege escalation. Successful exploitation allows an attacker to execute code with elevated privileges. CISA remediation due date: 2022-05-03. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2019-11634

Citrix Workspace Application and Receiver for Windows Remote Code Execution Vulnerability

Citrix Workspace Application and Receiver for Windows is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2019-11634). Citrix Workspace Application and Receiver for Windows contains remote code execution vulnerability resulting from local drive access preferences not being enforced into the clients' local drives. CISA remediation due date: 2022-05-03. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2019-11580

Atlassian Crowd and Crowd Data Center Remote Code Execution Vulnerability

Atlassian Crowd and Crowd Data Center is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2019-11580). Atlassian Crowd and Crowd Data Center contain a remote code execution vulnerability resulting from a pdkinstall development plugin being incorrectly enabled in release builds. CISA remediation due date: 2022-05-03. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2019-11539

Ivanti Pulse Connect Secure and Policy Secure Command Injection Vulnerability

Ivanti Pulse Connect Secure and Pulse Policy Secure is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2019-11539). Ivanti Pulse Connect Secure and Policy Secure allows an authenticated attacker from the admin web interface to inject and execute commands. CISA remediation due date: 2022-05-03. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2019-11510

Ivanti Pulse Connect Secure Arbitrary File Read Vulnerability

Ivanti Pulse Connect Secure is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2019-11510). Ivanti Pulse Connect Secure contains an arbitrary file read vulnerability that allows an unauthenticated remote attacker with network access via HTTPS to send a specially crafted URI. CISA remediation due date: 2022-05-03. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2019-0803

Microsoft Win32k Privilege Escalation Vulnerability

Microsoft Win32k is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2019-0803). Microsoft Win32k contains an unspecified vulnerability due to it failing to properly handle objects in memory causing privilege escalation. Successful exploitation allows an attacker to run code in kernel mode. CISA remediation due date: 2022-05-03. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2019-0708

Microsoft Remote Desktop Services Remote Code Execution Vulnerability

Microsoft Remote Desktop Services is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2019-0708). Microsoft Remote Desktop Services, formerly known as Terminal Service, contains an unspecified vulnerability that allows an unauthenticated attacker to connect to the target system using RDP and send specially crafted requests. Successful exploitation allows for remote code execution. The vulnerability is also known under the moniker of BlueKeep. CISA remediation due date: 2022-05-03. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2019-0604

Microsoft SharePoint Remote Code Execution Vulnerability

Microsoft SharePoint is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2019-0604). Microsoft SharePoint fails to check the source markup of an application package. An attacker who successfully exploits the vulnerability could run remote code in the context of the SharePoint application pool and the SharePoint server farm account. CISA remediation due date: 2022-05-03. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2018-7600

Drupal Core Remote Code Execution Vulnerability

Drupal Drupal Core is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2018-7600). Drupal Core contains a remote code execution vulnerability that could allow an attacker to exploit multiple attack vectors on a Drupal site, resulting in complete site compromise. CISA remediation due date: 2022-05-03. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2018-6789

Exim Buffer Overflow Vulnerability

Exim Exim is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2018-6789). Exim contains a buffer overflow vulnerability in the base64d function part of the SMTP listener that may allow for remote code execution. CISA remediation due date: 2022-05-03. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2018-4878

Adobe Flash Player Use-After-Free Vulnerability

Adobe Flash Player is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2018-4878). Adobe Flash Player contains a use-after-free vulnerability that could allow for code execution. CISA remediation due date: 2022-05-03. If you need help checking exposure, call (864) 335-9223.