Fixed Intel

CVE Tracker

Track known exploited vulnerabilities, CISA KEV alerts, and linked threat intelligence.

2,235

Total CVEs

1,590

CISA KEV

41

Known Exploits

8.8

Avg CVSS Score

Severity Distribution

CRITICAL 8
HIGH 1600
MEDIUM 7
INFO 620

Showing 20 of 1,590 CVEs · CISA KEV

CVE-2012-1889KEV
High

Microsoft XML Core Services contains a memory corruption vulnerability which could allow for remote code execution.

MicrosoftEPSS 92.9%
CVE-2019-15271KEV
High

A deserialization of untrusted data vulnerability in the web-based management interface of certain Cisco Small Business RV Series Routers could allow an attacker to execute code with root privileges.

CiscoEPSS 5.6%
CVE-2017-6862KEV
High

Multiple NETGEAR devices contain a buffer overflow vulnerability that allows for authentication bypass and remote code execution.

NETGEAREPSS 37.5%
CVE-2012-0151KEV
High

The Authenticode Signature Verification function in Microsoft Windows (WinVerifyTrust) does not properly validate the digest of a signed portable executable (PE) file, which allows user-assisted remote attackers to execute code.

MicrosoftEPSS 89.0%
CVE-2019-7192KEV
High

QNAP NAS devices running Photo Station contain an improper access control vulnerability allowing remote attackers to gain unauthorized access to the system.

QNAPEPSS 94.3%
CVE-2019-5825KEV
High

Google Chromium V8 Engine contains an out-of-bounds write vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

GoogleEPSS 73.7%
CVE-2019-7194KEV
High

QNAP devices running Photo Station contain an external control of file name or path vulnerability allowing remote attackers to access or modify system files.

QNAPEPSS 93.9%
CVE-2019-7195KEV
High

QNAP devices running Photo Station contain an external control of file name or path vulnerability allowing remote attackers to access or modify system files.

QNAPEPSS 94.1%
CVE-2010-2883KEV
High

Adobe Acrobat and Reader contain a stack-based buffer overflow vulnerability that allows remote attackers to execute code or cause denial-of-service (DoS).

AdobeEPSS 93.2%
CVE-2019-7193KEV
High

QNAP QTS contains an improper input validation vulnerability allowing remote attackers to inject code on the system.

QNAPEPSS 25.8%
CVE-2009-1862KEV
High

Adobe Acrobat and Reader and Adobe Flash Player allows remote attackers to execute code or cause denial-of-service (DoS).

AdobeEPSS 58.6%
CVE-2009-4324KEV
High

Use-after-free vulnerability in Adobe Acrobat and Reader allows remote attackers to execute code via a crafted PDF file.

AdobeEPSS 92.9%
CVE-2022-26134KEV
High

Atlassian Confluence Server and Data Center contain a remote code execution vulnerability that allows for an unauthenticated attacker to perform remote code execution.

AtlassianCVSS 9.8EPSS 94.4%
Exploit
CVE-2013-0431KEV
High

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle allows remote attackers to bypass the Java security sandbox.

OracleEPSS 91.6%
CVE-2016-0034KEV
High

Microsoft Silverlight mishandles negative offsets during decoding, which allows attackers to execute remote code or cause a denial-of-service (DoS).

MicrosoftEPSS 40.5%
CVE-2015-1671KEV
High

A remote code execution vulnerability exists when components of Windows, .NET Framework, Office, Lync, and Silverlight fail to properly handle TrueType fonts.

MicrosoftEPSS 85.9%
CVE-2010-0738KEV
High

The JMX-Console web application in JBossAs in Red Hat JBoss Enterprise Application Platform performs access control only for the GET and POST methods, which allows remote attackers to send requests to this application's GET handler by using a different method.

Red HatEPSS 90.9%
CVE-2015-0310KEV
High

Adobe Flash Player does not properly restrict discovery of memory addresses, which allows attackers to bypass the address space layout randomization (ASLR) protection mechanism.

AdobeEPSS 5.4%
CVE-2016-7256KEV
High

A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts. An attacker who successfully exploits this vulnerability could take control of the affected system.

MicrosoftEPSS 65.1%
CVE-2012-1710KEV
High

Unspecified vulnerability in the Oracle WebCenter Forms Recognition component in Oracle Fusion Middleware allows remote attackers to affect confidentiality, integrity, and availability via Unknown vectors related to Designer.

OracleEPSS 55.4%