Fixed Intel

CVE Tracker

Track known exploited vulnerabilities, CISA KEV alerts, and linked threat intelligence.

1,542

Total CVEs

1,542

CISA KEV

35

Known Exploits

9.3

Avg CVSS Score

Severity Distribution

HIGH 1542

Showing 20 of 1,542 CVEs · HIGH · CISA KEV

CVE-2010-4345KEV
High

Exim allows local users to gain privileges by leveraging the ability of the exim user account to specify an alternate configuration file with a directive that contains arbitrary commands.

EximEPSS 4.0%
CVE-2013-2251KEV
High

Apache Struts allows remote attackers to execute arbitrary Object-Graph Navigation Language (OGNL) expressions.

ApacheEPSS 94.3%
CVE-2012-1823KEV
High

sapi/cgi/cgi_main.c in PHP, when configured as a CGI script, does not properly handle query strings, which allows remote attackers to execute arbitrary code.

PHPCVSS 9.8EPSS 94.4%
Exploit
CVE-2016-10174KEV
High

The NETGEAR WNR2000v5 router contains a buffer overflow which can be exploited to achieve remote code execution.

NETGEAREPSS 89.8%
CVE-2009-2055KEV
High

Cisco IOS XR,when BGP is the configured routing feature, allows remote attackers to cause a denial-of-service (DoS).

CiscoEPSS 0.4%
CVE-2016-11021KEV
High

setSystemCommand on D-Link DCS-930L devices allows a remote attacker to execute code via an OS command.

D-LinkEPSS 91.3%
CVE-2013-5223KEV
High

A cross-site scripting (XSS) vulnerability exists in the D-Link DSL-2760U gateway, allowing remote authenticated users to inject arbitrary web script or HTML.

D-LinkEPSS 35.5%
CVE-2015-1427KEV
High

The Groovy scripting engine in Elasticsearch allows remote attackers to bypass the sandbox protection mechanism and execute arbitrary shell commands.

ElasticEPSS 92.3%
CVE-2015-3035KEV
High

Directory traversal vulnerability in multiple TP-Link Archer devices allows remote attackers to read arbitrary files via a .. (dot dot) in the PATH_INFO to login/.

TP-LinkEPSS 92.9%
CVE-2015-4068KEV
High

Directory traversal vulnerability in Arcserve UDP allows remote attackers to obtain sensitive information or cause a denial of service.

ArcserveEPSS 80.9%
CVE-2016-0752KEV
High

Directory traversal vulnerability in Action View in Ruby on Rails allows remote attackers to read arbitrary files.

RailsEPSS 92.7%
CVE-2010-4344KEV
High

Heap-based buffer overflow in the string_vformat function in string.c in Exim before 4.70 allows remote attackers to execute arbitrary code via an SMTP session.

EximEPSS 61.5%
CVE-2015-1187KEV
High

The ping tool in multiple D-Link and TRENDnet devices allow remote attackers to perform remote code execution.

D-Link and TRENDnetEPSS 81.2%
CVE-2022-26143KEV
High

A vulnerability has been identified in MiCollab and MiVoice Business Express that may allow a malicious actor to gain unauthorized access to sensitive information and services, cause performance degradations or a denial of service condition on the affected system.

MitelEPSS 89.2%
CVE-2019-11043KEV
High

In some versions of PHP in certain configurations of FPM setup, it is possible to cause FPM module to write past allocated buffers allowing the possibility of remote code execution.

PHPEPSS 94.1%
CVE-2021-42237KEV
High

Sitcore XP contains an insecure deserialization vulnerability which can allow for remote code execution.

SitecoreEPSS 94.4%
CVE-2014-6324KEV
High

The Kerberos Key Distribution Center (KDC) in Microsoft allows remote authenticated domain users to obtain domain administrator privileges.

MicrosoftEPSS 89.8%
CVE-2017-12615KEV
High

When running Apache Tomcat on Windows with HTTP PUTs enabled, it is possible to upload a JSP file to the server via a specially crafted request. This JSP could then be requested and any code it contained would be executed by the server.

ApacheEPSS 94.2%
CVE-2016-3309KEV
High

A privilege escalation vulnerability exists when the Windows kernel fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode.

MicrosoftEPSS 43.0%
CVE-2017-0101KEV
High

A privilege escalation vulnerability exists when the Windows Transaction Manager improperly handles objects in memory.

MicrosoftEPSS 64.4%