Skip to main content

Security Briefs

Page 17 of 23.

Alerts tracked

3939

Security flaws we track for Upstate SC businesses.

Known exploited

545

On CISA’s list of vulnerabilities attackers are actively using. Patch these first.

New exploited this month

2

Fresh additions to that CISA list since the first of the month.Feeds last synced Oct 6, 2026, 6:01 AM UTC.

Showing page 17 (24 alerts) of 545.

Actively exploited (KEV)Ransomware

CVE-2022-22954

VMware Workspace ONE Access and Identity Manager Server-Side Template Injection Vulnerability

VMware Workspace ONE Access and Identity Manager is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2022-22954). VMware Workspace ONE Access and Identity Manager allow for remote code execution due to server-side template injection. CISA remediation due date: 2022-05-05. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2022-24521

Microsoft Windows CLFS Driver Privilege Escalation Vulnerability

Microsoft Windows is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2022-24521). Microsoft Windows Common Log File System (CLFS) Driver contains an unspecified vulnerability that allows for privilege escalation. CISA remediation due date: 2022-05-04. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2018-7602

Drupal Core Remote Code Execution Vulnerability

Drupal Core is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2018-7602). A remote code execution vulnerability exists within multiple subsystems of Drupal that can allow attackers to exploit multiple attack vectors on a Drupal site. CISA remediation due date: 2022-05-04. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2018-20753

Kaseya VSA Remote Code Execution Vulnerability

Kaseya Virtual System/Server Administrator (VSA) is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2018-20753). Kaseya VSA RMM allows unprivileged remote attackers to execute PowerShell payloads on all managed devices. CISA remediation due date: 2022-05-04. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2021-42287

Microsoft Active Directory Domain Services Privilege Escalation Vulnerability

Microsoft Active Directory is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2021-42287). Microsoft Active Directory Domain Services contains an unspecified vulnerability that allows for privilege escalation. CISA remediation due date: 2022-05-02. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2021-42278

Microsoft Active Directory Domain Services Privilege Escalation Vulnerability

Microsoft Active Directory is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2021-42278). Microsoft Active Directory Domain Services contains an unspecified vulnerability that allows for privilege escalation. CISA remediation due date: 2022-05-02. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2017-0148

Microsoft SMBv1 Server Remote Code Execution Vulnerability

Microsoft SMBv1 server is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2017-0148). The SMBv1 server in Microsoft allows remote attackers to execute arbitrary code via crafted packets. CISA remediation due date: 2022-04-27. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2021-28799

QNAP NAS Improper Authorization Vulnerability

QNAP Network Attached Storage (NAS) is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2021-28799). QNAP NAS running HBS 3 contains an improper authorization vulnerability which can allow remote attackers to log in to a device. CISA remediation due date: 2022-04-21. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2018-10562

Dasan GPON Routers Command Injection Vulnerability

Dasan Gigabit Passive Optical Network (GPON) Routers is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2018-10562). Dasan GPON Routers contain an authentication bypass vulnerability. When combined with CVE-2018-10561, exploitation can allow an attacker to perform remote code execution. CISA remediation due date: 2022-04-21. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2021-38646

Microsoft Office Access Connectivity Engine Remote Code Execution Vulnerability

Microsoft Office is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2021-38646). Microsoft Office Access Connectivity Engine contains an unspecified vulnerability which can allow for remote code execution. CISA remediation due date: 2022-04-18. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2021-26085

Atlassian Confluence Server Pre-Authorization Arbitrary File Read Vulnerability

Atlassian Confluence Server is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2021-26085). Affected versions of Atlassian Confluence Server allow remote attackers to view restricted resources via a pre-authorization arbitrary file read vulnerability in the /s/ endpoint. CISA remediation due date: 2022-04-18. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2021-20028

SonicWall Secure Remote Access (SRA) SQL Injection Vulnerability

SonicWall Secure Remote Access (SRA) is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2021-20028). SonicWall Secure Remote Access (SRA) products contain an improper neutralization of a SQL Command leading to SQL injection. CISA remediation due date: 2022-04-18. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2018-8440

Microsoft Windows Privilege Escalation Vulnerability

Microsoft Windows is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2018-8440). An elevation of privilege vulnerability exists when Windows improperly handles calls to Advanced Local Procedure Call (ALPC). CISA remediation due date: 2022-04-18. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2018-8406

Microsoft DirectX Graphics Kernel Privilege Escalation Vulnerability

Microsoft DirectX Graphics Kernel (DXGKRNL) is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2018-8406). An elevation of privilege vulnerability exists when the DirectX Graphics Kernel (DXGKRNL) driver improperly handles objects in memory. CISA remediation due date: 2022-04-18. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2018-8405

Microsoft DirectX Graphics Kernel Privilege Escalation Vulnerability

Microsoft DirectX Graphics Kernel (DXGKRNL) is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2018-8405). An elevation of privilege vulnerability exists when the DirectX Graphics Kernel (DXGKRNL) driver improperly handles objects in memory. CISA remediation due date: 2022-04-18. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2017-0213

Microsoft Windows Privilege Escalation Vulnerability

Microsoft Windows is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2017-0213). Microsoft Windows COM Aggregate Marshaler allows for privilege escalation when an attacker runs a specially crafted application. CISA remediation due date: 2022-04-18. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2016-0189

Microsoft Internet Explorer Memory Corruption Vulnerability

Microsoft Internet Explorer is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2016-0189). The Microsoft JScript nd VBScript engines, as used in Internet Explorer and other products, allow attackers to execute remote code or cause a denial of service (memory corruption) via a crafted web site. CISA remediation due date: 2022-04-18. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2016-0151

Microsoft Windows CSRSS Security Feature Bypass Vulnerability

Microsoft Client-Server Run-time Subsystem (CSRSS) is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2016-0151). The Client-Server Run-time Subsystem (CSRSS) in Microsoft mismanages process tokens, which allows local users to gain privileges via a crafted application. CISA remediation due date: 2022-04-18. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2013-2551

Microsoft Internet Explorer Use-After-Free Vulnerability

Microsoft Internet Explorer is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2013-2551). Use-after-free vulnerability in Microsoft Internet Explorer allows remote attackers to execute remote code via a crafted web site that triggers access to a deleted object. CISA remediation due date: 2022-04-18. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2013-2465

Oracle Java SE Unspecified Vulnerability

Oracle Java SE is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2013-2465). Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE allows remote attackers to affect confidentiality, integrity, and availability via Unknown vectors related to 2D CISA remediation due date: 2022-04-18. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2022-21999

Microsoft Windows Print Spooler Privilege Escalation Vulnerability

Microsoft Windows is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2022-21999). Microsoft Windows Print Spooler contains an unspecified vulnerability which can allow for privilege escalation. CISA remediation due date: 2022-04-15. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2021-42237

Sitecore XP Remote Command Execution Vulnerability

Sitecore XP is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2021-42237). Sitcore XP contains an insecure deserialization vulnerability which can allow for remote code execution. CISA remediation due date: 2022-04-15. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2021-22941

Citrix ShareFile Improper Access Control Vulnerability

Citrix ShareFile is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2021-22941). Improper Access Control in Citrix ShareFile storage zones controller may allow an unauthenticated attacker to remotely compromise the storage zones controller. CISA remediation due date: 2022-04-15. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2020-2021

Palo Alto Networks PAN-OS Authentication Bypass Vulnerability

Palo Alto Networks PAN-OS is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2020-2021). Palo Alto Networks PAN-OS contains a vulnerability in SAML which allows an attacker to bypass authentication. CISA remediation due date: 2022-04-15. If you need help checking exposure, call (864) 335-9223.