Skip to main content

Security Briefs

Page 18 of 21.

Alerts tracked

2627

Security flaws we track for Upstate SC businesses.

Known exploited

503

On CISA’s list of vulnerabilities attackers are actively using. Patch these first.

New exploited this month

43

Fresh additions to that CISA list since the first of the month.Feeds last synced Aug 20, 2026, 6:00 AM UTC.

Showing page 18 (24 alerts) of 503.

Actively exploited (KEV)Ransomware

CVE-2020-0796

Microsoft SMBv3 Remote Code Execution Vulnerability

Microsoft SMBv3 is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2020-0796). A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol handles certain requests. An attacker who successfully exploited the vulnerability could gain the ability to execute code on the target server or client. CISA remediation due date: 2022-08-10. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2017-10271

Oracle Corporation WebLogic Server Remote Code Execution Vulnerability

Oracle WebLogic Server is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2017-10271). Oracle Corporation WebLogic Server contains a vulnerability that allows for remote code execution. CISA remediation due date: 2022-08-10. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2017-0145

Microsoft SMBv1 Remote Code Execution Vulnerability

Microsoft SMBv1 is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2017-0145). The SMBv1 server in multiple Microsoft Windows versions allows remote attackers to execute arbitrary code via crafted packets. CISA remediation due date: 2022-08-10. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2017-0144

Microsoft SMBv1 Remote Code Execution Vulnerability

Microsoft SMBv1 is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2017-0144). The SMBv1 server in multiple Microsoft Windows versions allows remote attackers to execute arbitrary code via crafted packets. CISA remediation due date: 2022-08-10. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2022-21882

Microsoft Win32k Privilege Escalation Vulnerability

Microsoft Win32k is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2022-21882). Microsoft Win32k contains an unspecified vulnerability that allows for privilege escalation. CISA remediation due date: 2022-02-18. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2021-20038

SonicWall SMA 100 Appliances Stack-Based Buffer Overflow Vulnerability

SonicWall SMA 100 Appliances is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2021-20038). SonicWall SMA 100 devies are vulnerable to an unauthenticated stack-based buffer overflow vulnerability where exploitation can result in code execution. CISA remediation due date: 2022-02-11. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2020-0787

Microsoft Windows Background Intelligent Transfer Service (BITS) Improper Privilege Management Vulnerability

Microsoft Windows is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2020-0787). Microsoft Windows BITS is vulnerable to to a privilege elevation vulnerability if it improperly handles symbolic links. An actor can exploit this vulnerability to execute arbitrary code with system-level privileges. CISA remediation due date: 2022-07-28. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2018-8453

Microsoft Win32k Privilege Escalation Vulnerability

Microsoft Win32k is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2018-8453). Microsoft Windows Win32k contains a vulnerability that allows an attacker to escalate privileges. CISA remediation due date: 2022-07-21. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2021-21975

VMware Server Side Request Forgery in vRealize Operations Manager API vulnerability

VMware vRealize Operations Manager API is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2021-21975). Server Side Request Forgery (SSRF) in vRealize Operations Manager API prior to 8.4 may allow a malicious actor with network access to the vRealize Operations Manager API to perform a SSRF attack to steal administrative credentials. CISA remediation due date: 2022-02-01. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2019-2725

Oracle WebLogic Server, Injection vulnerability

Oracle WebLogic Server is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2019-2725). Injection vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). CISA remediation due date: 2022-07-10. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2019-1579

Palo Alto Networks PAN-OS Remote Code Execution Vulnerability

Palo Alto Networks PAN-OS is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2019-1579). Remote Code Execution in PAN-OS with GlobalProtect Portal or GlobalProtect Gateway Interface enabled. CISA remediation due date: 2022-07-10. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2019-1458

Microsoft Win32k Privilege Escalation Vulnerability

Microsoft Win32k is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2019-1458). A privilege escalation vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k EoP. CISA remediation due date: 2022-07-10. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2018-13383

Fortinet FortiOS and FortiProxy Out-of-bounds Write vulnerability

Fortinet FortiOS and FortiProxy is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2018-13383). A heap buffer overflow in Fortinet FortiOS and FortiProxy may cause the SSL VPN web service termination for logged in users. CISA remediation due date: 2022-07-10. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2018-13382

Fortinet FortiOS and FortiProxy Improper Authorization vulnerability

Fortinet FortiOS and FortiProxy is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2018-13382). An Improper Authorization vulnerability in Fortinet FortiOS and FortiProxy under SSL VPN web portal allows an unauthenticated attacker to modify the password. CISA remediation due date: 2022-07-10. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2021-43890

Microsoft Windows AppX Installer Spoofing Vulnerability

Microsoft Windows is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2021-43890). Microsoft Windows AppX Installer contains a spoofing vulnerability which has a high impacts to confidentiality, integrity, and availability. CISA remediation due date: 2021-12-29. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2021-44228

Apache Log4j2 Remote Code Execution Vulnerability

Apache Log4j2 is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2021-44228). Apache Log4j2 contains a vulnerability where JNDI features do not protect against attacker-controlled JNDI-related endpoints, allowing for remote code execution. CISA remediation due date: 2021-12-24. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2017-12149

Red Hat JBoss Application Server Remote Code Execution Vulnerability

Red Hat JBoss Application Server is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2017-12149). The JBoss Application Server, shipped with Red Hat Enterprise Application Platform 5.2, allows an attacker to execute arbitrary code via crafted serialized data. CISA remediation due date: 2022-06-10. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2021-40438

Apache HTTP Server-Side Request Forgery (SSRF) vulnerability

Apache Apache is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2021-40438). A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. This issue affects Apache HTTP Server 2.4.48 and earlier. CISA remediation due date: 2021-12-15. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2021-42321

Microsoft Exchange Server Remote Code Execution Vulnerability

Microsoft Exchange is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2021-42321). An authenticated attacker could leverage improper validation in cmdlet arguments within Microsoft Exchange and perform remote code execution. CISA remediation due date: 2021-12-01. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2021-40449

Microsoft Windows Win32k Privilege Escalation Vulnerability

Microsoft Windows is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2021-40449). Unspecified vulnerability allows for an authenticated user to escalate privileges. CISA remediation due date: 2021-12-01. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2021-42258

BQE BillQuick Web Suite SQL Injection Vulnerability

BQE BillQuick Web Suite is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2021-42258). BQE BillQuick Web Suite contains an SQL injection vulnerability when accessing the username parameter that may allow for unauthenticated, remote code execution. CISA remediation due date: 2021-11-17. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2021-42013

Apache HTTP Server Path Traversal Vulnerability

Apache HTTP Server is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2021-42013). Apache HTTP Server contains a path traversal vulnerability that allows an attacker to perform remote code execution if files outside directories configured by Alias-like directives are not under default require all denied or if CGI scripts are enabled. This CVE ID resolves an incomplete patch for CVE-2021-41773. CISA remediation due date: 2021-11-17. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2021-41773

Apache HTTP Server Path Traversal Vulnerability

Apache HTTP Server is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2021-41773). Apache HTTP Server contains a path traversal vulnerability that allows an attacker to perform remote code execution if files outside directories configured by Alias-like directives are not under default �require all denied� or if CGI scripts are enabled. The original patch issued under this CVE ID is insufficient, please review remediation information under CVE-2021-42013. CISA remediation due date: 2021-11-17. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2021-40539

Zoho ManageEngine ADSelfService Plus Authentication Bypass Vulnerability

Zoho ManageEngine is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2021-40539). Zoho ManageEngine ADSelfService Plus contains an authentication bypass vulnerability affecting the REST API URLs which allow for remote code execution. CISA remediation due date: 2021-11-17. If you need help checking exposure, call (864) 335-9223.