Skip to main content

Security Briefs

Page 21 of 21.

Alerts tracked

2627

Security flaws we track for Upstate SC businesses.

Known exploited

503

On CISA’s list of vulnerabilities attackers are actively using. Patch these first.

New exploited this month

43

Fresh additions to that CISA list since the first of the month.Feeds last synced Aug 20, 2026, 6:00 AM UTC.

Showing page 21 (23 alerts) of 503.

Actively exploited (KEV)Ransomware

CVE-2019-1367

Microsoft Internet Explorer Scripting Engine Memory Corruption Vulnerability

Microsoft Internet Explorer is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2019-1367). Microsoft Internet Explorer contains a memory corruption vulnerability in how the scripting engine handles objects in memory. Successful exploitation allows for remote code execution in the context of the current user. CISA remediation due date: 2022-05-03. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2019-13608

Citrix StoreFront Server XML External Entity (XXE) Processing Vulnerability

Citrix StoreFront Server is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2019-13608). Citrix StoreFront Server contains an XML External Entity (XXE) processing vulnerability that may allow an unauthenticated attacker to retrieve potentially sensitive information. CISA remediation due date: 2022-05-03. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2019-1215

Microsoft Windows Privilege Escalation Vulnerability

Microsoft Windows is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2019-1215). Microsoft Windows contains an unspecified vulnerability due to the way ws2ifsl.sys (Winsock) handles objects in memory, allowing for privilege escalation. Successful exploitation allows an attacker to execute code with elevated privileges. CISA remediation due date: 2022-05-03. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2019-11634

Citrix Workspace Application and Receiver for Windows Remote Code Execution Vulnerability

Citrix Workspace Application and Receiver for Windows is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2019-11634). Citrix Workspace Application and Receiver for Windows contains remote code execution vulnerability resulting from local drive access preferences not being enforced into the clients' local drives. CISA remediation due date: 2022-05-03. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2019-11580

Atlassian Crowd and Crowd Data Center Remote Code Execution Vulnerability

Atlassian Crowd and Crowd Data Center is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2019-11580). Atlassian Crowd and Crowd Data Center contain a remote code execution vulnerability resulting from a pdkinstall development plugin being incorrectly enabled in release builds. CISA remediation due date: 2022-05-03. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2019-11539

Ivanti Pulse Connect Secure and Policy Secure Command Injection Vulnerability

Ivanti Pulse Connect Secure and Pulse Policy Secure is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2019-11539). Ivanti Pulse Connect Secure and Policy Secure allows an authenticated attacker from the admin web interface to inject and execute commands. CISA remediation due date: 2022-05-03. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2019-11510

Ivanti Pulse Connect Secure Arbitrary File Read Vulnerability

Ivanti Pulse Connect Secure is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2019-11510). Ivanti Pulse Connect Secure contains an arbitrary file read vulnerability that allows an unauthenticated remote attacker with network access via HTTPS to send a specially crafted URI. CISA remediation due date: 2022-05-03. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2019-0803

Microsoft Win32k Privilege Escalation Vulnerability

Microsoft Win32k is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2019-0803). Microsoft Win32k contains an unspecified vulnerability due to it failing to properly handle objects in memory causing privilege escalation. Successful exploitation allows an attacker to run code in kernel mode. CISA remediation due date: 2022-05-03. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2019-0708

Microsoft Remote Desktop Services Remote Code Execution Vulnerability

Microsoft Remote Desktop Services is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2019-0708). Microsoft Remote Desktop Services, formerly known as Terminal Service, contains an unspecified vulnerability that allows an unauthenticated attacker to connect to the target system using RDP and send specially crafted requests. Successful exploitation allows for remote code execution. The vulnerability is also known under the moniker of BlueKeep. CISA remediation due date: 2022-05-03. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2019-0604

Microsoft SharePoint Remote Code Execution Vulnerability

Microsoft SharePoint is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2019-0604). Microsoft SharePoint fails to check the source markup of an application package. An attacker who successfully exploits the vulnerability could run remote code in the context of the SharePoint application pool and the SharePoint server farm account. CISA remediation due date: 2022-05-03. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2018-7600

Drupal Core Remote Code Execution Vulnerability

Drupal Drupal Core is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2018-7600). Drupal Core contains a remote code execution vulnerability that could allow an attacker to exploit multiple attack vectors on a Drupal site, resulting in complete site compromise. CISA remediation due date: 2022-05-03. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2018-6789

Exim Buffer Overflow Vulnerability

Exim Exim is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2018-6789). Exim contains a buffer overflow vulnerability in the base64d function part of the SMTP listener that may allow for remote code execution. CISA remediation due date: 2022-05-03. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2018-4878

Adobe Flash Player Use-After-Free Vulnerability

Adobe Flash Player is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2018-4878). Adobe Flash Player contains a use-after-free vulnerability that could allow for code execution. CISA remediation due date: 2022-05-03. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2018-2380

SAP Customer Relationship Management (CRM) Path Traversal Vulnerability

SAP Customer Relationship Management (CRM) is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2018-2380). SAP Customer Relationship Management (CRM) contains a path traversal vulnerability that allows an attacker to exploit insufficient validation of path information provided by users. CISA remediation due date: 2022-05-03. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2018-13379

Fortinet FortiOS SSL VPN Path Traversal Vulnerability

Fortinet FortiOS is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2018-13379). Fortinet FortiOS SSL VPN web portal contains a path traversal vulnerability that may allow an unauthenticated attacker to download FortiOS system files through specially crafted HTTP resource requests. CISA remediation due date: 2022-05-03. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2018-0802

Microsoft Office Memory Corruption Vulnerability

Microsoft Office is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2018-0802). Microsoft Office contains a memory corruption vulnerability due to the way objects are handled in memory. Successful exploitation allows for remote code execution in the context of the current user. This vulnerability is known to be chained with CVE-2018-0798. CISA remediation due date: 2022-05-03. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2017-9822

DotNetNuke (DNN) Remote Code Execution Vulnerability

DotNetNuke (DNN) DotNetNuke (DNN) is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2017-9822). DotNetNuke (DNN) contains a vulnerability that may allow for remote code execution via cookie deserialization. CISA remediation due date: 2022-05-03. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2017-5638

Apache Struts Remote Code Execution Vulnerability

Apache Struts is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2017-5638). Apache Struts Jakarta Multipart parser allows for malicious file upload using the Content-Type value, leading to remote code execution. CISA remediation due date: 2022-05-03. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2017-11882

Microsoft Office Memory Corruption Vulnerability

Microsoft Office is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2017-11882). Microsoft Office contains a memory corruption vulnerability that allows remote code execution in the context of the current user. CISA remediation due date: 2022-05-03. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2017-0199

Microsoft Office and WordPad Remote Code Execution Vulnerability

Microsoft Office and WordPad is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2017-0199). Microsoft Office and WordPad contain an unspecified vulnerability due to the way the applications parse specially crafted files. Successful exploitation allows for remote code execution. CISA remediation due date: 2022-05-03. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2017-0143

Microsoft Windows Server Message Block (SMBv1) Remote Code Execution Vulnerability

Microsoft Windows is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2017-0143). Microsoft Windows Server Message Block 1.0 (SMBv1) contains an unspecified vulnerability that allows for remote code execution. CISA remediation due date: 2022-05-03. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2016-0167

Microsoft Win32k Privilege Escalation Vulnerability

Microsoft Win32k is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2016-0167). Microsoft Win32k contains an unspecified vulnerability that allows for privilege escalation via a crafted application CISA remediation due date: 2022-05-03. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2014-1812

Microsoft Windows Group Policy Preferences Password Privilege Escalation Vulnerability

Microsoft Windows is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2014-1812). Microsoft Windows Active Directory contains a privilege escalation vulnerability due to the way it distributes passwords that are configured using Group Policy preferences. An authenticated attacker who successfully exploits the vulnerability could decrypt the passwords and use them to elevate privileges on the domain. CISA remediation due date: 2022-05-03. If you need help checking exposure, call (864) 335-9223.