Security Briefs
Page 16 of 21.
Alerts tracked
2627
Security flaws we track for Upstate SC businesses.
Known exploited
503
On CISA’s list of vulnerabilities attackers are actively using. Patch these first.
New exploited this month
43
Fresh additions to that CISA list since the first of the month.Feeds last synced Aug 20, 2026, 6:00 AM UTC.
Showing page 16 (24 alerts) of 503.
Microsoft DirectX Graphics Kernel Privilege Escalation Vulnerability
Microsoft DirectX Graphics Kernel (DXGKRNL) is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2018-8406). An elevation of privilege vulnerability exists when the DirectX Graphics Kernel (DXGKRNL) driver improperly handles objects in memory. CISA remediation due date: 2022-04-18. If you need help checking exposure, call (864) 335-9223.
Microsoft DirectX Graphics Kernel Privilege Escalation Vulnerability
Microsoft DirectX Graphics Kernel (DXGKRNL) is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2018-8405). An elevation of privilege vulnerability exists when the DirectX Graphics Kernel (DXGKRNL) driver improperly handles objects in memory. CISA remediation due date: 2022-04-18. If you need help checking exposure, call (864) 335-9223.
Microsoft Windows Privilege Escalation Vulnerability
Microsoft Windows is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2017-0213). Microsoft Windows COM Aggregate Marshaler allows for privilege escalation when an attacker runs a specially crafted application. CISA remediation due date: 2022-04-18. If you need help checking exposure, call (864) 335-9223.
Microsoft Internet Explorer Memory Corruption Vulnerability
Microsoft Internet Explorer is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2016-0189). The Microsoft JScript nd VBScript engines, as used in Internet Explorer and other products, allow attackers to execute remote code or cause a denial of service (memory corruption) via a crafted web site. CISA remediation due date: 2022-04-18. If you need help checking exposure, call (864) 335-9223.
Microsoft Windows CSRSS Security Feature Bypass Vulnerability
Microsoft Client-Server Run-time Subsystem (CSRSS) is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2016-0151). The Client-Server Run-time Subsystem (CSRSS) in Microsoft mismanages process tokens, which allows local users to gain privileges via a crafted application. CISA remediation due date: 2022-04-18. If you need help checking exposure, call (864) 335-9223.
Microsoft Internet Explorer Use-After-Free Vulnerability
Microsoft Internet Explorer is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2013-2551). Use-after-free vulnerability in Microsoft Internet Explorer allows remote attackers to execute remote code via a crafted web site that triggers access to a deleted object. CISA remediation due date: 2022-04-18. If you need help checking exposure, call (864) 335-9223.
Oracle Java SE Unspecified Vulnerability
Oracle Java SE is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2013-2465). Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE allows remote attackers to affect confidentiality, integrity, and availability via Unknown vectors related to 2D CISA remediation due date: 2022-04-18. If you need help checking exposure, call (864) 335-9223.
Microsoft Windows Print Spooler Privilege Escalation Vulnerability
Microsoft Windows is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2022-21999). Microsoft Windows Print Spooler contains an unspecified vulnerability which can allow for privilege escalation. CISA remediation due date: 2022-04-15. If you need help checking exposure, call (864) 335-9223.
Sitecore XP Remote Command Execution Vulnerability
Sitecore XP is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2021-42237). Sitcore XP contains an insecure deserialization vulnerability which can allow for remote code execution. CISA remediation due date: 2022-04-15. If you need help checking exposure, call (864) 335-9223.
Citrix ShareFile Improper Access Control Vulnerability
Citrix ShareFile is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2021-22941). Improper Access Control in Citrix ShareFile storage zones controller may allow an unauthenticated attacker to remotely compromise the storage zones controller. CISA remediation due date: 2022-04-15. If you need help checking exposure, call (864) 335-9223.
Palo Alto Networks PAN-OS Authentication Bypass Vulnerability
Palo Alto Networks PAN-OS is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2020-2021). Palo Alto Networks PAN-OS contains a vulnerability in SAML which allows an attacker to bypass authentication. CISA remediation due date: 2022-04-15. If you need help checking exposure, call (864) 335-9223.
Webmin Command Injection Vulnerability
Webmin Webmin is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2019-15107). An issue was discovered in Webmin. The parameter old in password_change.cgi contains a command injection vulnerability. CISA remediation due date: 2022-04-15. If you need help checking exposure, call (864) 335-9223.
PHP FastCGI Process Manager (FPM) Buffer Overflow Vulnerability
PHP FastCGI Process Manager (FPM) is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2019-11043). In some versions of PHP in certain configurations of FPM setup, it is possible to cause FPM module to write past allocated buffers allowing the possibility of remote code execution. CISA remediation due date: 2022-04-15. If you need help checking exposure, call (864) 335-9223.
VMware Tanzu Spring Data Commons Property Binder Vulnerability
VMware Tanzu Spring Data Commons is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2018-1273). Spring Data Commons contains a property binder vulnerability which can allow an attacker to perform remote code execution. CISA remediation due date: 2022-04-15. If you need help checking exposure, call (864) 335-9223.
Quest KACE System Management Appliance Remote Command Execution Vulnerability
Quest KACE System Management Appliance is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2018-11138). The '/common/download_agent_installer.php' script in the Quest KACE System Management Appliance is accessible by anonymous users and can be abused to perform remote code execution. CISA remediation due date: 2022-04-15. If you need help checking exposure, call (864) 335-9223.
Apache Tomcat on Windows Remote Code Execution Vulnerability
Apache Tomcat is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2017-12615). When running Apache Tomcat on Windows with HTTP PUTs enabled, it is possible to upload a JSP file to the server via a specially crafted request. This JSP could then be requested and any code it contained would be executed by the server. CISA remediation due date: 2022-04-15. If you need help checking exposure, call (864) 335-9223.
Microsoft Windows SMB Remote Code Execution Vulnerability
Microsoft Windows is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2017-0146). The SMBv1 server in Microsoft Windows allows remote attackers to perform remote code execution. CISA remediation due date: 2022-04-15. If you need help checking exposure, call (864) 335-9223.
Adobe ColdFusion Directory Traversal Vulnerability
Adobe ColdFusion is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2010-2861). A directory traversal vulnerability exists in the administrator console in Adobe ColdFusion which allows remote attackers to read arbitrary files. CISA remediation due date: 2022-04-15. If you need help checking exposure, call (864) 335-9223.
Microsoft Windows Universal Plug and Play (UPnP) Service Privilege Escalation Vulnerability
Microsoft Windows is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2019-1405). A privilege escalation vulnerability exists when the Windows UPnP service improperly allows COM object creation. CISA remediation due date: 2022-04-05. If you need help checking exposure, call (864) 335-9223.
Microsoft Windows Privilege Escalation Vulnerability
Microsoft Windows is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2019-1322). A privilege escalation vulnerability exists when Windows improperly handles authentication requests. An attacker who successfully exploited this vulnerability could run processes in an elevated context. CISA remediation due date: 2022-04-05. If you need help checking exposure, call (864) 335-9223.
Microsoft Windows Error Reporting Manager Privilege Escalation Vulnerability
Microsoft Windows is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2019-1315). A privilege escalation vulnerability exists when Windows Error Reporting manager improperly handles hard links. An attacker who successfully exploited this vulnerability could overwrite a targeted file leading to an elevated status. CISA remediation due date: 2022-04-05. If you need help checking exposure, call (864) 335-9223.
Microsoft Windows AppX Deployment Server Privilege Escalation Vulnerability
Microsoft Windows is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2019-1253). A privilege escalation vulnerability exists when the Windows AppX Deployment Server improperly handles junctions. CISA remediation due date: 2022-04-05. If you need help checking exposure, call (864) 335-9223.
Microsoft Windows AppX Deployment Service (AppXSVC) Privilege Escalation Vulnerability
Microsoft Windows is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2019-1129). A privilege escalation vulnerability exists when Windows AppXSVC improperly handles hard links. An attacker who successfully exploited this vulnerability could run processes in an elevated context. CISA remediation due date: 2022-04-05. If you need help checking exposure, call (864) 335-9223.
Microsoft Task Scheduler Privilege Escalation Vulnerability
Microsoft Task Scheduler is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2019-1069). A privilege escalation vulnerability exists in the way the Task Scheduler Service validates certain file operations. CISA remediation due date: 2022-04-05. If you need help checking exposure, call (864) 335-9223.