Security Briefs
Page 23 of 23.
Alerts tracked
3939
Security flaws we track for Upstate SC businesses.
Known exploited
545
On CISA’s list of vulnerabilities attackers are actively using. Patch these first.
New exploited this month
2
Fresh additions to that CISA list since the first of the month.Feeds last synced Oct 6, 2026, 6:01 AM UTC.
Showing page 23 (17 alerts) of 545.
Microsoft Remote Desktop Services Remote Code Execution Vulnerability
Microsoft Remote Desktop Services is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2019-0708). Microsoft Remote Desktop Services, formerly known as Terminal Service, contains an unspecified vulnerability that allows an unauthenticated attacker to connect to the target system using RDP and send specially crafted requests. Successful exploitation allows for remote code execution. The vulnerability is also known under the moniker of BlueKeep. CISA remediation due date: 2022-05-03. If you need help checking exposure, call (864) 335-9223.
Microsoft SharePoint Remote Code Execution Vulnerability
Microsoft SharePoint is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2019-0604). Microsoft SharePoint fails to check the source markup of an application package. An attacker who successfully exploits the vulnerability could run remote code in the context of the SharePoint application pool and the SharePoint server farm account. CISA remediation due date: 2022-05-03. If you need help checking exposure, call (864) 335-9223.
Drupal Core Remote Code Execution Vulnerability
Drupal Drupal Core is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2018-7600). Drupal Core contains a remote code execution vulnerability that could allow an attacker to exploit multiple attack vectors on a Drupal site, resulting in complete site compromise. CISA remediation due date: 2022-05-03. If you need help checking exposure, call (864) 335-9223.
Exim Buffer Overflow Vulnerability
Exim Exim is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2018-6789). Exim contains a buffer overflow vulnerability in the base64d function part of the SMTP listener that may allow for remote code execution. CISA remediation due date: 2022-05-03. If you need help checking exposure, call (864) 335-9223.
Adobe Flash Player Use-After-Free Vulnerability
Adobe Flash Player is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2018-4878). Adobe Flash Player contains a use-after-free vulnerability that could allow for code execution. CISA remediation due date: 2022-05-03. If you need help checking exposure, call (864) 335-9223.
SAP Customer Relationship Management (CRM) Path Traversal Vulnerability
SAP Customer Relationship Management (CRM) is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2018-2380). SAP Customer Relationship Management (CRM) contains a path traversal vulnerability that allows an attacker to exploit insufficient validation of path information provided by users. CISA remediation due date: 2022-05-03. If you need help checking exposure, call (864) 335-9223.
Fortinet FortiOS SSL VPN Path Traversal Vulnerability
Fortinet FortiOS is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2018-13379). Fortinet FortiOS SSL VPN web portal contains a path traversal vulnerability that may allow an unauthenticated attacker to download FortiOS system files through specially crafted HTTP resource requests. CISA remediation due date: 2022-05-03. If you need help checking exposure, call (864) 335-9223.
Microsoft Office Memory Corruption Vulnerability
Microsoft Office is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2018-0802). Microsoft Office contains a memory corruption vulnerability due to the way objects are handled in memory. Successful exploitation allows for remote code execution in the context of the current user. This vulnerability is known to be chained with CVE-2018-0798. CISA remediation due date: 2022-05-03. If you need help checking exposure, call (864) 335-9223.
DotNetNuke (DNN) Remote Code Execution Vulnerability
DotNetNuke (DNN) DotNetNuke (DNN) is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2017-9822). DotNetNuke (DNN) contains a vulnerability that may allow for remote code execution via cookie deserialization. CISA remediation due date: 2022-05-03. If you need help checking exposure, call (864) 335-9223.
Apache Struts Remote Code Execution Vulnerability
Apache Struts is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2017-5638). Apache Struts Jakarta Multipart parser allows for malicious file upload using the Content-Type value, leading to remote code execution. CISA remediation due date: 2022-05-03. If you need help checking exposure, call (864) 335-9223.
Microsoft Office Memory Corruption Vulnerability
Microsoft Office is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2017-11882). Microsoft Office contains a memory corruption vulnerability that allows remote code execution in the context of the current user. CISA remediation due date: 2022-05-03. If you need help checking exposure, call (864) 335-9223.
Microsoft Office and WordPad Remote Code Execution Vulnerability
Microsoft Office and WordPad is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2017-0199). Microsoft Office and WordPad contain an unspecified vulnerability due to the way the applications parse specially crafted files. Successful exploitation allows for remote code execution. CISA remediation due date: 2022-05-03. If you need help checking exposure, call (864) 335-9223.
Microsoft Windows Server Message Block (SMBv1) Remote Code Execution Vulnerability
Microsoft Windows is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2017-0143). Microsoft Windows Server Message Block 1.0 (SMBv1) contains an unspecified vulnerability that allows for remote code execution. CISA remediation due date: 2022-05-03. If you need help checking exposure, call (864) 335-9223.
Microsoft Win32k Privilege Escalation Vulnerability
Microsoft Win32k is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2016-7255). Microsoft Win32k kernel-mode driver fails to properly handle objects in memory which allows for privilege escalation. Successful exploitation allows an attacker to run code in kernel mode. CISA remediation due date: 2022-05-03. If you need help checking exposure, call (864) 335-9223.
Microsoft Win32k Privilege Escalation Vulnerability
Microsoft Win32k is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2016-0167). Microsoft Win32k contains an unspecified vulnerability that allows for privilege escalation via a crafted application CISA remediation due date: 2022-05-03. If you need help checking exposure, call (864) 335-9223.
Microsoft Windows Group Policy Preferences Password Privilege Escalation Vulnerability
Microsoft Windows is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2014-1812). Microsoft Windows Active Directory contains a privilege escalation vulnerability due to the way it distributes passwords that are configured using Group Policy preferences. An authenticated attacker who successfully exploits the vulnerability could decrypt the passwords and use them to elevate privileges on the domain. CISA remediation due date: 2022-05-03. If you need help checking exposure, call (864) 335-9223.
Microsoft MSCOMCTL.OCX Remote Code Execution Vulnerability
Microsoft MSCOMCTL.OCX is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2012-0158). Microsoft MSCOMCTL.OCX contains an unspecified vulnerability that allows for remote code execution, allowing an attacker to take complete control of an affected system under the context of the current user. CISA remediation due date: 2022-05-03. If you need help checking exposure, call (864) 335-9223.