Fixed Intel

CVE Tracker

Track known exploited vulnerabilities, CISA KEV alerts, and linked threat intelligence.

2,235

Total CVEs

1,590

CISA KEV

41

Known Exploits

8.8

Avg CVSS Score

Severity Distribution

CRITICAL 8
HIGH 1600
MEDIUM 7
INFO 620

Showing 20 of 1,590 CVEs · CISA KEV

CVE-2019-1132KEV
High

A privilege escalation vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory.

MicrosoftEPSS 35.6%
CVE-2022-26486KEV
High

Mozilla Firefox contains a use-after-free vulnerability in WebGPU IPC Framework which can be exploited to perform arbitrary code execution.

MozillaEPSS 2.2%
CVE-2017-6077KEV
High

NETGEAR DGN2200 wireless routers contain a vulnerability that allows for remote code execution.

NETGEAREPSS 86.1%
CVE-2016-6277KEV
High

NETGEAR confirmed multiple routers allow unauthenticated web pages to pass form input directly to the command-line interface, permitting remote code execution.

NETGEAREPSS 94.3%
CVE-2019-11581KEV
High

Atlassian Jira Server and Data Center contain a server-side template injection vulnerability which can allow for remote code execution.

AtlassianEPSS 94.4%
CVE-2020-8218KEV
High

A code injection vulnerability exists in Pulse Connect Secure that allows an attacker to crafted a URI to perform an arbitrary code execution via the admin web interface.

Pulse SecureEPSS 91.1%
CVE-2013-0629KEV
High

Adobe Coldfusion contains a directory traversal vulnerability, which could permit an unauthorized user access to restricted directories.

AdobeEPSS 84.0%
CVE-2009-3960KEV
High

Adobe BlazeDS, which is utilized in LifeCycle and Coldfusion, contains a vulnerability that allows for information disclosure.

AdobeEPSS 88.7%
CVE-2013-0631KEV
High

Adobe Coldfusion contains an unspecified vulnerability, which could result in information disclosure from a compromised server.

AdobeEPSS 83.3%
CVE-2021-21973KEV
High

VMware vCenter Server and Cloud Foundation Server contain a SSRF vulnerability due to improper validation of URLs in a vCenter Server plugin. This allows for information disclosure.

VMwareEPSS 90.3%
CVE-2013-0625KEV
High

Adobe Coldfusion contains an authentication bypass vulnerability, which could result in an unauthorized user gaining administrative access.

AdobeEPSS 78.1%
CVE-2022-26485KEV
High

Mozilla Firefox contains a use-after-free vulnerability in XSLT parameter processing which can be exploited to perform arbitrary code execution.

MozillaEPSS 7.1%
CVE-2015-2387KEV
High

ATMFD.DLL in the Adobe Type Manager Font Driver in Microsoft Windows Server allows local users to gain privileges via a crafted application.

MicrosoftEPSS 31.2%
CVE-2012-0507KEV
High

An incorrect type vulnerability exists in the Concurrency component of Oracle's Java Runtime Environment allows an attacker to remotely execute arbitrary code.

OracleEPSS 93.6%
CVE-2015-4902KEV
High

Unspecified vulnerability in Oracle Java SE allows remote attackers to affect integrity via Unknown vectors related to deployment.

OracleEPSS 7.7%
CVE-2010-0188KEV
High

Unspecified vulnerability in Adobe Reader and Acrobat allows attackers to cause a denial of service or possibly execute arbitrary code.

AdobeEPSS 93.4%
CVE-2008-2992KEV
High

Adobe Acrobat and Reader contain an input validation issue in a JavaScript method that could potentially lead to remote code execution.

AdobeEPSS 93.7%
CVE-2022-20700KEV
High

A vulnerability in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code elevate privileges, execute arbitrary commands, bypass authentication and authorization protections, fetch and run unsigned software, or cause a denial of service (DoS).

CiscoEPSS 21.8%
CVE-2004-0210KEV
High

A privilege elevation vulnerability exists in the POSIX subsystem. This vulnerability could allow a logged on user to take complete control of the system.

MicrosoftEPSS 3.7%
CVE-2017-12319KEV
High

A vulnerability in the Border Gateway Protocol (BGP) over an Ethernet Virtual Private Network (EVPN) for Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause the device to reload, resulting in a denial of service (DoS) condition, or potentially corrupt the BGP routing table, which could result in network instability.

CiscoEPSS 1.3%