Fixed Intel

CVE Tracker

Track known exploited vulnerabilities, CISA KEV alerts, and linked threat intelligence.

1,542

Total CVEs

1,542

CISA KEV

35

Known Exploits

9.3

Avg CVSS Score

Severity Distribution

HIGH 1542

Showing 20 of 1,542 CVEs · HIGH · CISA KEV

CVE-2017-12234KEV
High

There is a vulnerability in the implementation of the Common Industrial Protocol (CIP) feature in Cisco IOS could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial of service.

CiscoEPSS 6.5%
CVE-2017-6627KEV
High

A vulnerability in the UDP processing code of Cisco IOS and IOS XE could allow an unauthenticated, remote attacker to cause the input queue of an affected system to hold UDP packets, causing an interface queue wedge and denial of service.

CiscoEPSS 10.8%
CVE-2017-12232KEV
High

A vulnerability in the implementation of a protocol in Cisco Integrated Services Routers Generation 2 (ISR G2) Routers running Cisco IOS could allow an unauthenticated, adjacent attacker to cause an affected device to reload, resulting in a denial of service.

CiscoEPSS 1.0%
CVE-2017-6736KEV
High

The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE contains a vulnerability that could allow an authenticated, remote attacker to remotely execute code.

CiscoEPSS 89.0%
CVE-2017-0261KEV
High

Microsoft Office contains a use-after-free vulnerability which can allow for remote code execution.

MicrosoftEPSS 92.9%
CVE-2017-6743KEV
High

The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE contains a vulnerability that could allow an authenticated, remote attacker to remotely execute code.

CiscoEPSS 28.8%
CVE-2017-6738KEV
High

The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE contains a vulnerability that could allow an authenticated, remote attacker to remotely execute code.

CiscoEPSS 28.8%
CVE-2009-1123KEV
High

The kernel in Microsoft Windows does not properly validate changes to unspecified kernel objects, which allows local users to gain privileges via a crafted application.

MicrosoftEPSS 4.3%
CVE-2015-1701KEV
High

An unspecified vulnerability exists in the Win32k.sys kernel-mode driver in Microsoft Windows Server that allows a local attacker to execute arbitrary code with elevated privileges.

MicrosoftEPSS 89.7%
CVE-2016-1019KEV
High

Adobe Flash Player allows remote attackers to cause a denial of service or possibly execute arbitrary code.

AdobeEPSS 72.4%
CVE-2016-7262KEV
High

A security feature bypass vulnerability exists when Microsoft Office improperly handles input. An attacker who successfully exploited the vulnerability could execute arbitrary commands.

MicrosoftEPSS 87.1%
CVE-2016-7193KEV
High

Microsoft Office contains a memory corruption vulnerability which can allow for remote code execution.

MicrosoftEPSS 71.2%
CVE-2009-3129KEV
High

Microsoft Office Excel allows remote attackers to execute arbitrary code via a spreadsheet with a FEATHEADER record containing an invalid cbHdrData size element that affects a pointer offset.

MicrosoftEPSS 91.6%
CVE-2015-2545KEV
High

Microsoft Office allows remote attackers to execute arbitrary code via a crafted EPS image.

MicrosoftEPSS 93.4%
CVE-2016-5195KEV
High

Race condition in mm/gup.c in the Linux kernel allows local users to escalate privileges.

LinuxEPSS 94.2%
CVE-2015-5119KEV
High

A use-after-free vulnerability exists within the ActionScript 3 ByteArray class in Adobe Flash Player that allows an attacker to perform remote code execution.

AdobeEPSS 93.2%
CVE-2013-3897KEV
High

A use-after-free vulnerability exists within CDisplayPointer in Microsoft Internet Explorer that allows an attacker to remotely execute arbitrary code.

MicrosoftEPSS 88.2%
CVE-2016-4117KEV
High

An access of resource using incompatible type vulnerability exists within Adobe Flash Player that allows an attacker to perform remote code execution.

AdobeEPSS 93.1%
CVE-2015-4902KEV
High

Unspecified vulnerability in Oracle Java SE allows remote attackers to affect integrity via Unknown vectors related to deployment.

OracleEPSS 7.7%
CVE-2012-0507KEV
High

An incorrect type vulnerability exists in the Concurrency component of Oracle's Java Runtime Environment allows an attacker to remotely execute arbitrary code.

OracleEPSS 93.6%