Fixed Intel

CVE Tracker

Track known exploited vulnerabilities, CISA KEV alerts, and linked threat intelligence.

2,235

Total CVEs

1,590

CISA KEV

41

Known Exploits

8.8

Avg CVSS Score

Severity Distribution

CRITICAL 8
HIGH 1600
MEDIUM 7
INFO 620

Showing 20 of 1,590 CVEs · CISA KEV

CVE-2013-2423KEV
High

Unspecified vulnerability in hotspot for Java Runtime Environment (JRE) allows remote attackers to affect integrity.

OracleEPSS 93.4%
CVE-2015-0071KEV
High

Microsoft Internet Explorer allows remote attackers to bypass the address space layout randomization (ASLR) protection mechanism via a crafted web site.

MicrosoftEPSS 37.0%
CVE-2015-2425KEV
High

Microsoft Internet Explorer contains a memory corruption vulnerability that allows remote attackers to execute code or cause denial-of-service (DoS).

MicrosoftEPSS 34.1%
CVE-2014-0546KEV
High

Adobe Reader and Acrobat on Windows allow attackers to bypass a sandbox protection mechanism, and consequently execute native code in a privileged context.

AdobeEPSS 29.7%
CVE-2010-1428KEV
High

Unauthenticated access to the JBoss Application Server Web Console (/web-console) is blocked by default. However, it was found that this block was incomplete, and only blocked GET and POST HTTP verbs. A remote attacker could use this flaw to gain access to sensitive information.

Red HatEPSS 65.3%
CVE-2014-4123KEV
High

Microsoft Internet Explorer contains an unspecified vulnerability that allows remote attackers to gain privileges via a crafted web site.

MicrosoftEPSS 53.6%
CVE-2014-3153KEV
High

The futex_requeue function in kernel/futex.c in Linux kernel does not ensure that calls have two different futex addresses, which allows local users to gain privileges.

LinuxEPSS 68.9%
CVE-2017-18362KEV
High

ConnectWise ManagedITSync integration for Kaseya VSA is vulnerable to unauthenticated remote commands that allow full direct access to the Kaseya VSA database.

KaseyaEPSS 80.3%
CVE-2017-0022KEV
High

Microsoft XML Core Services (MSXML) improperly handles objects in memory, allowing attackers to test for files on disk via a crafted web site.

MicrosoftEPSS 44.1%
CVE-2017-8543KEV
High

Microsoft Windows allows an attacker to take control of the affected system when Windows Search fails to handle objects in memory.

MicrosoftEPSS 83.8%
CVE-2016-6367KEV
High

A vulnerability in the command-line interface (CLI) parser of Cisco ASA software could allow an authenticated, local attacker to create a denial-of-service (DoS) condition or potentially execute code.

CiscoEPSS 23.1%
CVE-2018-8611KEV
High

A privilege escalation vulnerability exists when the Windows kernel fails to properly handle objects in memory.

MicrosoftEPSS 16.4%
CVE-2016-4656KEV
High

A memory corruption vulnerability in Apple iOS kernel allows attackers to execute code in a privileged context or cause a denial-of-service (DoS) via a crafted application.

AppleEPSS 66.7%
CVE-2016-4657KEV
High

Apple iOS WebKit contains a memory corruption vulnerability that allows attackers to execute remote code or cause a denial-of-service (DoS) via a crafted web site. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing.

AppleEPSS 78.4%
CVE-2017-8291KEV
High

Artifex Ghostscript allows -dSAFER bypass and remote command execution via .rsdparams type confusion with a "/OutputFile.

ArtifexEPSS 92.7%
CVE-2016-0162KEV
High

An information disclosure vulnerability exists when Internet Explorer does not properly handle JavaScript. The vulnerability could allow an attacker to detect specific files on the user's computer.

MicrosoftEPSS 38.0%
CVE-2017-0005KEV
High

The Graphics Device Interface (GDI) in Microsoft Windows allows local users to gain privileges via a crafted application.

MicrosoftEPSS 8.0%
CVE-2016-4655KEV
High

The Apple iOS kernel allows attackers to obtain sensitive information from memory via a crafted application.

AppleEPSS 82.1%
CVE-2017-0210KEV
High

A privilege escalation vulnerability exists when Internet Explorer does not properly enforce cross-domain policies, which could allow an attacker to access information.

MicrosoftEPSS 38.0%
CVE-2018-19943KEV
High

A cross-site scripting vulnerability affecting QNAP NAS File Station could allow remote attackers to inject malicious code.

QNAPEPSS 5.5%