Fixed Intel

CVE Tracker

Track known exploited vulnerabilities, CISA KEV alerts, and linked threat intelligence.

2,235

Total CVEs

1,590

CISA KEV

41

Known Exploits

8.8

Avg CVSS Score

Severity Distribution

CRITICAL 8
HIGH 1600
MEDIUM 7
INFO 620

Showing 20 of 1,585 CVEs · HIGH · CISA KEV

CVE-2018-8373KEV
High

A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer.

MicrosoftEPSS 82.4%
CVE-2019-1003030KEV
High

Jenkins Matrix Project plugin contains a vulnerability which can allow users to escape the sandbox, opening opportunity to perform remote code execution.

JenkinsEPSS 93.1%
CVE-2018-11138KEV
High

The '/common/download_agent_installer.php' script in the Quest KACE System Management Appliance is accessible by anonymous users and can be abused to perform remote code execution.

QuestEPSS 93.4%
CVE-2019-12991KEV
High

Authenticated Command Injection in Citrix SD-WAN Appliance and NetScaler SD-WAN Appliance.

CitrixEPSS 81.0%
CVE-2017-6334KEV
High

dnslookup.cgi on NETGEAR DGN2200 devices with firmware through 10.0.0.50 allows remote authenticated users to execute arbitrary OS commands

NETGEAREPSS 89.2%
CVE-2019-10068KEV
High

Kentico contains a failure to validate security headers. This deserialization can led to unauthenticated remote code execution.

KenticoEPSS 93.9%
CVE-2018-0125KEV
High

A vulnerability in the web interface of the Cisco VPN Routers could allow an unauthenticated, remote attacker to execute arbitrary code as root and gain full control of an affected system.

CiscoEPSS 39.6%
CVE-2018-8414KEV
High

A remote code execution vulnerability exists when the Windows Shell does not properly validate file paths.

MicrosoftEPSS 87.9%
CVE-2020-1956KEV
High

Apache Kylin contains an OS command injection vulnerability which could permit an attacker to perform remote code execution.

ApacheEPSS 93.9%
CVE-2016-7892KEV
High

Adobe Flash Player has an exploitable use-after-free vulnerability in the TextField class.

AdobeEPSS 23.3%
CVE-2017-12615KEV
High

When running Apache Tomcat on Windows with HTTP PUTs enabled, it is possible to upload a JSP file to the server via a specially crafted request. This JSP could then be requested and any code it contained would be executed by the server.

ApacheEPSS 94.2%
CVE-2020-9054KEV
High

Multiple Zyxel network-attached storage (NAS) devices contain a pre-authentication command injection vulnerability, which may allow a remote, unauthenticated attacker to execute arbitrary code.

ZyxelEPSS 94.3%
CVE-2019-2616KEV
High

Oracle BI Publisher, formerly XML Publisher, contains an unspecified vulnerability that allows for various unauthorized actions. Open-source reporting attributes this vulnerability to allowing for authentication bypass.

OracleEPSS 94.2%
CVE-2017-12617KEV
High

When running Apache Tomcat, it is possible to upload a JSP file to the server via a specially crafted request. This JSP could then be requested and any code it contained would be executed by the server.

ApacheEPSS 94.4%
CVE-2022-21999KEV
High

Microsoft Windows Print Spooler contains an unspecified vulnerability which can allow for privilege escalation.

MicrosoftEPSS 72.7%
CVE-2017-0146KEV
High

The SMBv1 server in Microsoft Windows allows remote attackers to perform remote code execution.

MicrosoftEPSS 93.3%
CVE-2017-6316KEV
High

A vulnerability has been identified in the management interface of Citrix NetScaler SD-WAN Enterprise and Standard Edition and Citrix CloudBridge Virtual WAN Edition that could result in an unauthenticated, remote attacker being able to execute arbitrary code as a root user. This vulnerability also affects XenMobile Server.

CitrixEPSS 87.8%
CVE-2019-16920KEV
High

Multiple D-Link routers contain a command injection vulnerability which can allow attackers to achieve full system compromise.

D-LinkEPSS 94.4%
CVE-2009-1151KEV
High

Setup script used to generate configuration can be fooled using a crafted POST request to include arbitrary PHP code in generated configuration file.

phpMyAdminEPSS 93.0%
CVE-2014-0130KEV
High

Directory traversal vulnerability in actionpack/lib/abstract_controller/base.rb in the implicit-render implementation in Ruby on Rails allows remote attackers to read arbitrary files via a crafted request.

RailsEPSS 45.4%