Fixed Intel

CVE Tracker

Track known exploited vulnerabilities, CISA KEV alerts, and linked threat intelligence.

2,235

Total CVEs

1,590

CISA KEV

41

Known Exploits

8.8

Avg CVSS Score

Severity Distribution

CRITICAL 8
HIGH 1600
MEDIUM 7
INFO 620

Showing 20 of 1,590 CVEs · CISA KEV

CVE-2022-41091KEV
High

Microsoft Windows Mark of the Web (MOTW) contains a security feature bypass vulnerability resulting in a limited loss of integrity and availability of security features.

MicrosoftEPSS 7.0%
CVE-2022-41128KEV
High

Microsoft Windows contains an unspecified vulnerability in the JScript9 scripting language which allows for remote code execution.

MicrosoftEPSS 39.2%
CVE-2021-25369KEV
High

Samsung mobile devices using Mali GPU contains an improper access control vulnerability in sec_log file. Exploitation of the vulnerability exposes sensitive kernel information to the userspace. This vulnerability was chained with CVE-2021-25337 and CVE-2021-25370.

SamsungEPSS 0.2%
CVE-2022-3723KEV
High

Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

GoogleEPSS 0.5%
CVE-2022-42827KEV
High

Apple iOS and iPadOS kernel contain an out-of-bounds write vulnerability which can allow an application to perform code execution with kernel privileges.

AppleEPSS 0.2%
CVE-2018-19322KEV
High

The GPCIDrv and GDrv low-level drivers in GIGABYTE App Center, AORUS Graphics Engine, XTREME Gaming Engine, and OC GURU II expose functionality to read/write data from/to IO ports. This could be leveraged in a number of ways to ultimately run code with elevated privileges.

GIGABYTEEPSS 2.9%
CVE-2018-19320KEV
High

The GDrv low-level driver in GIGABYTE App Center, AORUS Graphics Engine, XTREME Gaming Engine, and OC GURU II exposes ring0 memcpy-like functionality that could allow a local attacker to take complete control of the affected system.

GIGABYTEEPSS 38.7%
CVE-2020-3153KEV
High

Cisco AnyConnect Secure Mobility Client for Windows allows for incorrect handling of directory paths. An attacker with valid credentials on Windows would be able to copy malicious files to arbitrary locations with system level privileges. This could include DLL pre-loading, DLL hijacking, and other related attacks.

CiscoEPSS 25.1%
CVE-2020-3433KEV
High

Cisco AnyConnect Secure Mobility Client for Windows interprocess communication (IPC) channel allows for insufficient validation of resources that are loaded by the application at run time. An attacker with valid credentials on Windows could execute code on the affected machine with SYSTEM privileges.

CiscoEPSS 4.5%
CVE-2018-19323KEV
High

The GPCIDrv and GDrv low-level drivers in GIGABYTE App Center, AORUS Graphics Engine, XTREME Gaming Engine, and OC GURU expose functionality to read and write arbitrary physical memory. This could be leveraged by a local attacker to elevate privileges.

GIGABYTEEPSS 14.7%
CVE-2018-19321KEV
High

The GPCIDrv and GDrv low-level drivers in GIGABYTE App Center, AORUS Graphics Engine, XTREME Gaming Engine, and OC GURU II expose functionality to read and write arbitrary physical memory. This could be leveraged by a local attacker to elevate privileges.

GIGABYTEEPSS 40.0%
CVE-2022-41352KEV
High

Synacor Zimbra Collaboration Suite (ZCS) allows an attacker to upload arbitrary files using cpio package to gain incorrect access to any other user accounts.

SynacorEPSS 94.0%
CVE-2021-3493KEV
High

The overlayfs stacking file system in Linux kernel does not properly validate the application of file capabilities against user namespaces, which could lead to privilege escalation.

LinuxEPSS 76.8%
CVE-2022-40684KEV
High

Fortinet FortiOS, FortiProxy, and FortiSwitchManager contain an authentication bypass vulnerability that could allow an unauthenticated attacker to perform operations on the administrative interface via specially crafted HTTP or HTTPS requests.

FortinetEPSS 94.4%
CVE-2022-41033KEV
High

Microsoft Windows COM+ Event System Service contains an unspecified vulnerability that allows for privilege escalation.

MicrosoftEPSS 1.2%
CVE-2022-36804KEV
High

Multiple API endpoints of Atlassian Bitbucket Server and Data Center contain a command injection vulnerability where an attacker with access to a public Bitbucket repository, or with read permissions to a private one, can execute code by sending a malicious HTTP request.

AtlassianEPSS 94.4%
CVE-2022-41082KEV
High

Microsoft Exchange Server contains an unspecified vulnerability that allows for authenticated remote code execution. Dubbed "ProxyNotShell," this vulnerability is chainable with CVE-2022-41040 which allows for the remote code execution.

MicrosoftEPSS 91.7%
CVE-2022-41040KEV
High

Microsoft Exchange Server allows for server-side request forgery. Dubbed "ProxyNotShell," this vulnerability is chainable with CVE-2022-41082 which allows for remote code execution.

MicrosoftEPSS 94.2%
CVE-2022-3236KEV
High

A code injection vulnerability in the User Portal and Webadmin of Sophos Firewall allows for remote code execution.

SophosEPSS 92.9%
CVE-2022-35405KEV
High

Zoho ManageEngine PAM360, Password Manager Pro, and Access Manager Plus contain an unspecified vulnerability that allows for remote code execution.

ZohoEPSS 94.2%