Fixed Intel

CVE Tracker

Track known exploited vulnerabilities, CISA KEV alerts, and linked threat intelligence.

2,235

Total CVEs

1,590

CISA KEV

41

Known Exploits

8.8

Avg CVSS Score

Severity Distribution

CRITICAL 8
HIGH 1600
MEDIUM 7
INFO 620

Showing 20 of 1,585 CVEs · HIGH · CISA KEV

CVE-2017-12237KEV
High

A vulnerability in the Internet Key Exchange Version 2 (IKEv2) module of Cisco IOS and Cisco IOS XE could allow an unauthenticated, remote attacker to cause high CPU utilization, traceback messages, or a reload of an affected device that leads to a denial of service.

CiscoEPSS 5.3%
CVE-2013-1675KEV
High

Mozilla Firefox does not properly initialize data structures for the nsDOMSVGZoomEvent::mPreviousScale and nsDOMSVGZoomEvent::mNewScale functions, which allows remote attackers to obtain sensitive information from process memory via a crafted web site.

MozillaEPSS 4.7%
CVE-2017-12231KEV
High

A vulnerability in the implementation of Network Address Translation (NAT) functionality in Cisco IOS could allow an unauthenticated, remote attacker to cause a denial of service.

CiscoEPSS 6.8%
CVE-2018-8298KEV
High

The ChakraCore scripting engine contains a type confusion vulnerability which can allow for remote code execution.

ChakraCoreEPSS 90.3%
CVE-2017-12233KEV
High

There is a vulnerability in the implementation of the Common Industrial Protocol (CIP) feature in Cisco IOS could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial of service.

CiscoEPSS 6.5%
CVE-2022-20701KEV
High

A vulnerability in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code elevate privileges, execute arbitrary commands, bypass authentication and authorization protections, fetch and run unsigned software, or cause a denial of service (DoS).

CiscoEPSS 6.1%
CVE-2019-1652KEV
High

A vulnerability in the web-based management interface of Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers could allow an authenticated, remote attacker with administrative privileges on an affected device to execute arbitrary commands.

CiscoEPSS 93.0%
CVE-2022-20699KEV
High

A vulnerability in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code elevate privileges, execute arbitrary commands, bypass authentication and authorization protections, fetch and run unsigned software, or cause a denial of service (DoS).

CiscoEPSS 89.9%
CVE-2020-11899KEV
High

The Treck TCP/IP stack contains an IPv6 out-of-bounds read vulnerability.

Treck TCP/IP stackEPSS 33.3%
CVE-2021-41379KEV
High

Microsoft Windows Installer contains an unspecified vulnerability that allows for privilege escalation.

MicrosoftEPSS 1.2%
CVE-2015-3043KEV
High

A memory corruption vulnerability exists in Adobe Flash Player that allows an attacker to perform remote code execution.

AdobeEPSS 83.9%
CVE-2013-3346KEV
High

Adobe Reader and Acrobat contain a memory corruption vulnerability which can allow attackers to execute arbitrary code or cause a denial of service.

AdobeEPSS 89.9%
CVE-2019-16928KEV
High

Exim contains an out-of-bounds write vulnerability which can allow for remote code execution.

EximEPSS 89.8%
CVE-2017-11292KEV
High

Adobe Flash Player contains a type confusion vulnerability which can allow for remote code execution.

AdobeEPSS 21.2%
CVE-2020-1938KEV
High

Apache Tomcat treats Apache JServ Protocol (AJP) connections as having higher trust than, for example, a similar HTTP connection. If such connections are available to an attacker, they can be exploited.

ApacheCVSS 9.8EPSS 94.5%
Exploit
CVE-2015-1642KEV
High

Microsoft Office contains a memory corruption vulnerability that allows remote attackers to execute arbitrary code via a crafted document.

MicrosoftEPSS 72.9%
CVE-2022-20708KEV
High

A vulnerability in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code elevate privileges, execute arbitrary commands, bypass authentication and authorization protections, fetch and run unsigned software, or cause a denial of service (DoS).

CiscoEPSS 13.0%
CVE-2013-0641KEV
High

A buffer overflow vulnerability exists in Adobe Reader which allows an attacker to perform remote code execution.

AdobeEPSS 88.0%
CVE-2015-2424KEV
High

Microsoft PowerPoint allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted Office document.

MicrosoftEPSS 84.3%
CVE-2014-4114KEV
High

A vulnerability exists in Windows Object Linking & Embedding (OLE) that could allow remote code execution if a user opens a file that contains a specially crafted OLE object.

MicrosoftEPSS 92.1%