Fixed Intel

CVE Tracker

Track known exploited vulnerabilities, CISA KEV alerts, and linked threat intelligence.

1,542

Total CVEs

1,542

CISA KEV

35

Known Exploits

9.3

Avg CVSS Score

Severity Distribution

HIGH 1542

Showing 20 of 1,542 CVEs · HIGH · CISA KEV

CVE-2016-7892KEV
High

Adobe Flash Player has an exploitable use-after-free vulnerability in the TextField class.

AdobeEPSS 23.3%
CVE-2019-6340KEV
High

In Drupal Core, some field types do not properly sanitize data from non-form sources. This can lead to arbitrary PHP code execution in some cases.

DrupalCVSS 8.1EPSS 94.4%
Exploit
CVE-2019-2616KEV
High

Oracle BI Publisher, formerly XML Publisher, contains an unspecified vulnerability that allows for various unauthorized actions. Open-source reporting attributes this vulnerability to allowing for authentication bypass.

OracleEPSS 94.2%
CVE-2017-12617KEV
High

When running Apache Tomcat, it is possible to upload a JSP file to the server via a specially crafted request. This JSP could then be requested and any code it contained would be executed by the server.

ApacheEPSS 94.4%
CVE-2020-9054KEV
High

Multiple Zyxel network-attached storage (NAS) devices contain a pre-authentication command injection vulnerability, which may allow a remote, unauthenticated attacker to execute arbitrary code.

ZyxelEPSS 94.3%
CVE-2017-0146KEV
High

The SMBv1 server in Microsoft Windows allows remote attackers to perform remote code execution.

MicrosoftEPSS 93.3%
CVE-2017-6316KEV
High

A vulnerability has been identified in the management interface of Citrix NetScaler SD-WAN Enterprise and Standard Edition and Citrix CloudBridge Virtual WAN Edition that could result in an unauthenticated, remote attacker being able to execute arbitrary code as a root user. This vulnerability also affects XenMobile Server.

CitrixEPSS 87.8%
CVE-2019-16920KEV
High

Multiple D-Link routers contain a command injection vulnerability which can allow attackers to achieve full system compromise.

D-LinkEPSS 94.4%
CVE-2009-1151KEV
High

Setup script used to generate configuration can be fooled using a crafted POST request to include arbitrary PHP code in generated configuration file.

phpMyAdminEPSS 93.0%
CVE-2014-0130KEV
High

Directory traversal vulnerability in actionpack/lib/abstract_controller/base.rb in the implicit-render implementation in Ruby on Rails allows remote attackers to read arbitrary files via a crafted request.

RailsEPSS 45.4%
CVE-2015-0666KEV
High

Directory traversal vulnerability in the fmserver servlet in Cisco Prime Data Center Network Manager (DCNM) allows remote attackers to read arbitrary files.

CiscoEPSS 53.1%
CVE-2017-3881KEV
High

A vulnerability in the Cisco Cluster Management Protocol (CMP) processing code in Cisco IOS and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a reload of an affected device or remotely execute code with elevated privileges.

CiscoEPSS 94.3%
CVE-2014-6287KEV
High

The findMacroMarker function in parserLib.pas in Rejetto HTTP File Server (HFS or HttpFileServer) allows remote attackers to execute arbitrary programs.

RejettoEPSS 94.4%
CVE-2016-4171KEV
High

Unspecified vulnerability in Adobe Flash Player allows for remote code execution.

AdobeEPSS 50.5%
CVE-2016-1555KEV
High

Multiple NETGEAR Wireless Access Point devices allows unauthenticated web pages to pass form input directly to the command-line interface. Exploitation allows for arbitrary code execution.

NETGEAREPSS 94.3%
CVE-2014-3120KEV
High

Elasticsearch enables dynamic scripting, which allows remote attackers to execute arbitrary MVEL expressions and Java code.

ElasticEPSS 85.6%
CVE-2010-2861KEV
High

A directory traversal vulnerability exists in the administrator console in Adobe ColdFusion which allows remote attackers to read arbitrary files.

AdobeEPSS 94.3%
CVE-2014-6332KEV
High

OleAut32.dll in OLE in Microsoft Windows allows remote attackers to remotely execute code via a crafted web site.

MicrosoftEPSS 94.1%
CVE-2010-3035KEV
High

Cisco IOS XR, when BGP is the configured routing feature, allows remote attackers to cause a denial-of-service (DoS).

CiscoEPSS 3.2%
CVE-2013-4810KEV
High

HP ProCurve Manager (PCM), PCM+, Identity Driven Manager (IDM), and Application Lifecycle Management allow remote attackers to execute arbitrary code via a marshalled object to (1) EJBInvokerServlet or (2) JMXInvokerServlet.

Hewlett Packard (HP)EPSS 89.6%