Security Briefs
Page 111 of 111.
Alerts tracked
2651
Security flaws we track for Upstate SC businesses.
Known exploited
504
On CISA’s list of vulnerabilities attackers are actively using. Patch these first.
New exploited this month
60
Fresh additions to that CISA list since the first of the month.Feeds last synced Aug 24, 2026, 6:00 AM UTC.
Showing page 111 (11 alerts) of 2651.
SAP Customer Relationship Management (CRM) Path Traversal Vulnerability
SAP Customer Relationship Management (CRM) is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2018-2380). SAP Customer Relationship Management (CRM) contains a path traversal vulnerability that allows an attacker to exploit insufficient validation of path information provided by users. CISA remediation due date: 2022-05-03. If you need help checking exposure, call (864) 335-9223.
Fortinet FortiOS SSL VPN Path Traversal Vulnerability
Fortinet FortiOS is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2018-13379). Fortinet FortiOS SSL VPN web portal contains a path traversal vulnerability that may allow an unauthenticated attacker to download FortiOS system files through specially crafted HTTP resource requests. CISA remediation due date: 2022-05-03. If you need help checking exposure, call (864) 335-9223.
Microsoft Office Memory Corruption Vulnerability
Microsoft Office is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2018-0802). Microsoft Office contains a memory corruption vulnerability due to the way objects are handled in memory. Successful exploitation allows for remote code execution in the context of the current user. This vulnerability is known to be chained with CVE-2018-0798. CISA remediation due date: 2022-05-03. If you need help checking exposure, call (864) 335-9223.
DotNetNuke (DNN) Remote Code Execution Vulnerability
DotNetNuke (DNN) DotNetNuke (DNN) is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2017-9822). DotNetNuke (DNN) contains a vulnerability that may allow for remote code execution via cookie deserialization. CISA remediation due date: 2022-05-03. If you need help checking exposure, call (864) 335-9223.
Apache Struts Remote Code Execution Vulnerability
Apache Struts is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2017-5638). Apache Struts Jakarta Multipart parser allows for malicious file upload using the Content-Type value, leading to remote code execution. CISA remediation due date: 2022-05-03. If you need help checking exposure, call (864) 335-9223.
Microsoft Office Memory Corruption Vulnerability
Microsoft Office is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2017-11882). Microsoft Office contains a memory corruption vulnerability that allows remote code execution in the context of the current user. CISA remediation due date: 2022-05-03. If you need help checking exposure, call (864) 335-9223.
Microsoft Office and WordPad Remote Code Execution Vulnerability
Microsoft Office and WordPad is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2017-0199). Microsoft Office and WordPad contain an unspecified vulnerability due to the way the applications parse specially crafted files. Successful exploitation allows for remote code execution. CISA remediation due date: 2022-05-03. If you need help checking exposure, call (864) 335-9223.
Microsoft Windows Server Message Block (SMBv1) Remote Code Execution Vulnerability
Microsoft Windows is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2017-0143). Microsoft Windows Server Message Block 1.0 (SMBv1) contains an unspecified vulnerability that allows for remote code execution. CISA remediation due date: 2022-05-03. If you need help checking exposure, call (864) 335-9223.
Microsoft Win32k Privilege Escalation Vulnerability
Microsoft Win32k is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2016-0167). Microsoft Win32k contains an unspecified vulnerability that allows for privilege escalation via a crafted application CISA remediation due date: 2022-05-03. If you need help checking exposure, call (864) 335-9223.
Microsoft Windows Group Policy Preferences Password Privilege Escalation Vulnerability
Microsoft Windows is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2014-1812). Microsoft Windows Active Directory contains a privilege escalation vulnerability due to the way it distributes passwords that are configured using Group Policy preferences. An authenticated attacker who successfully exploits the vulnerability could decrypt the passwords and use them to elevate privileges on the domain. CISA remediation due date: 2022-05-03. If you need help checking exposure, call (864) 335-9223.
Microsoft MSCOMCTL.OCX Remote Code Execution Vulnerability
Microsoft MSCOMCTL.OCX is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2012-0158). Microsoft MSCOMCTL.OCX contains an unspecified vulnerability that allows for remote code execution, allowing an attacker to take complete control of an affected system under the context of the current user. CISA remediation due date: 2022-05-03. If you need help checking exposure, call (864) 335-9223.