Fixed Intel

CVE Tracker

Track known exploited vulnerabilities, CISA KEV alerts, and linked threat intelligence.

1,542

Total CVEs

1,542

CISA KEV

35

Known Exploits

9.3

Avg CVSS Score

Severity Distribution

HIGH 1542

Showing 20 of 1,542 CVEs · HIGH · CISA KEV

CVE-2019-1253KEV
High

A privilege escalation vulnerability exists when the Windows AppX Deployment Server improperly handles junctions.

MicrosoftEPSS 30.2%
CVE-2019-1069KEV
High

A privilege escalation vulnerability exists in the way the Task Scheduler Service validates certain file operations.

MicrosoftEPSS 30.5%
CVE-2019-1315KEV
High

A privilege escalation vulnerability exists when Windows Error Reporting manager improperly handles hard links. An attacker who successfully exploited this vulnerability could overwrite a targeted file leading to an elevated status.

MicrosoftEPSS 7.5%
CVE-2019-1322KEV
High

A privilege escalation vulnerability exists when Windows improperly handles authentication requests. An attacker who successfully exploited this vulnerability could run processes in an elevated context.

MicrosoftEPSS 36.5%
CVE-2019-1129KEV
High

A privilege escalation vulnerability exists when Windows AppXSVC improperly handles hard links. An attacker who successfully exploited this vulnerability could run processes in an elevated context.

MicrosoftEPSS 3.1%
CVE-2019-1132KEV
High

A privilege escalation vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory.

MicrosoftEPSS 35.6%
CVE-2018-8120KEV
High

A privilege escalation vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory.

MicrosoftEPSS 94.1%
CVE-2019-0543KEV
High

A privilege escalation vulnerability exists when Windows improperly handles authentication requests. An attacker who successfully exploited this vulnerability could run processes in an elevated context.

MicrosoftEPSS 16.6%
CVE-2015-2546KEV
High

The kernel-mode driver in Microsoft Windows OS and Server allows local users to gain privileges via a crafted application.

MicrosoftEPSS 39.9%
CVE-2019-1064KEV
High

A privilege escalation vulnerability exists when Windows AppXSVC improperly handles hard links. An attacker who successfully exploited this vulnerability could run processes in an elevated context.

MicrosoftEPSS 11.3%
CVE-2019-1405KEV
High

A privilege escalation vulnerability exists when the Windows UPnP service improperly allows COM object creation.

MicrosoftEPSS 57.1%
CVE-2019-0841KEV
High

A privilege escalation vulnerability exists when Windows AppXSVC improperly handles hard links. An attacker who successfully exploited this vulnerability could run processes in an elevated context.

MicrosoftEPSS 82.7%
CVE-2020-5135KEV
High

A buffer overflow vulnerability in SonicOS allows a remote attacker to cause Denial of Service (DoS) and potentially execute arbitrary code by sending a malicious request to the firewall.

SonicWallEPSS 25.0%
CVE-2013-0629KEV
High

Adobe Coldfusion contains a directory traversal vulnerability, which could permit an unauthorized user access to restricted directories.

AdobeEPSS 84.0%
CVE-2013-0625KEV
High

Adobe Coldfusion contains an authentication bypass vulnerability, which could result in an unauthorized user gaining administrative access.

AdobeEPSS 78.1%
CVE-2017-6077KEV
High

NETGEAR DGN2200 wireless routers contain a vulnerability that allows for remote code execution.

NETGEAREPSS 86.1%
CVE-2016-6277KEV
High

NETGEAR confirmed multiple routers allow unauthenticated web pages to pass form input directly to the command-line interface, permitting remote code execution.

NETGEAREPSS 94.3%
CVE-2020-8218KEV
High

A code injection vulnerability exists in Pulse Connect Secure that allows an attacker to crafted a URI to perform an arbitrary code execution via the admin web interface.

Pulse SecureEPSS 91.1%
CVE-2022-26486KEV
High

Mozilla Firefox contains a use-after-free vulnerability in WebGPU IPC Framework which can be exploited to perform arbitrary code execution.

MozillaEPSS 2.2%
CVE-2019-11581KEV
High

Atlassian Jira Server and Data Center contain a server-side template injection vulnerability which can allow for remote code execution.

AtlassianEPSS 94.4%