Fixed Intel

CVE Tracker

Track known exploited vulnerabilities, CISA KEV alerts, and linked threat intelligence.

2,235

Total CVEs

1,590

CISA KEV

41

Known Exploits

8.8

Avg CVSS Score

Severity Distribution

CRITICAL 8
HIGH 1600
MEDIUM 7
INFO 620

Showing 20 of 1,585 CVEs · HIGH · CISA KEV

CVE-2017-12319KEV
High

A vulnerability in the Border Gateway Protocol (BGP) over an Ethernet Virtual Private Network (EVPN) for Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause the device to reload, resulting in a denial of service (DoS) condition, or potentially corrupt the BGP routing table, which could result in network instability.

CiscoEPSS 1.3%
CVE-2022-20700KEV
High

A vulnerability in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code elevate privileges, execute arbitrary commands, bypass authentication and authorization protections, fetch and run unsigned software, or cause a denial of service (DoS).

CiscoEPSS 21.8%
CVE-2008-3431KEV
High

An input validation vulnerability exists in the VBoxDrv.sys driver of Sun xVM VirtualBox which allows attackers to locally execute arbitrary code.

OracleEPSS 5.4%
CVE-2004-0210KEV
High

A privilege elevation vulnerability exists in the POSIX subsystem. This vulnerability could allow a logged on user to take complete control of the system.

MicrosoftEPSS 3.7%
CVE-2017-12235KEV
High

A vulnerability in the implementation of the PROFINET Discovery and Configuration Protocol (PN-DCP) for Cisco IOS could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial of service.

CiscoEPSS 4.9%
CVE-2010-3333KEV
High

A stack-based buffer overflow vulnerability exists in the parsing of RTF data in Microsoft Office and earlier allows an attacker to perform remote code execution.

MicrosoftEPSS 93.8%
CVE-2018-0155KEV
High

A vulnerability in the Bidirectional Forwarding Detection (BFD) offload implementation of Cisco Catalyst 4500 Series Switches and Cisco Catalyst 4500-X Series Switches could allow an unauthenticated, remote attacker to cause a crash of the iosd process, causing a denial-of-service (DoS) condition.

CiscoEPSS 14.5%
CVE-2013-0640KEV
High

An memory corruption vulnerability exists in the acroform.dll in Adobe Reader that allows an attacker to perform remote code execution.

AdobeEPSS 92.4%
CVE-2015-2590KEV
High

An unspecified vulnerability exists within Oracle Java Runtime Environment that allows an attacker to perform remote code execution.

OracleEPSS 61.5%
CVE-2022-20703KEV
High

A vulnerability in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code elevate privileges, execute arbitrary commands, bypass authentication and authorization protections, fetch and run unsigned software, or cause a denial of service (DoS).

CiscoEPSS 2.0%
CVE-2015-7645KEV
High

Adobe Flash Player allows remote attackers to execute arbitrary code via a crafted SWF file.

AdobeEPSS 84.5%
CVE-2011-1889KEV
High

A remote code execution vulnerability exists in the Forefront Threat Management Gateway (TMG) Firewall Client Winsock provider that could allow code execution in the security context of the client application.

MicrosoftEPSS 85.4%
CVE-2014-0496KEV
High

Adobe Reader and Acrobat contain a use-after-free vulnerability which can allow for code execution.

AdobeEPSS 74.9%
CVE-2015-2387KEV
High

ATMFD.DLL in the Adobe Type Manager Font Driver in Microsoft Windows Server allows local users to gain privileges via a crafted application.

MicrosoftEPSS 31.2%
CVE-2012-0507KEV
High

An incorrect type vulnerability exists in the Concurrency component of Oracle's Java Runtime Environment allows an attacker to remotely execute arbitrary code.

OracleEPSS 93.6%
CVE-2015-4902KEV
High

Unspecified vulnerability in Oracle Java SE allows remote attackers to affect integrity via Unknown vectors related to deployment.

OracleEPSS 7.7%
CVE-2016-4117KEV
High

An access of resource using incompatible type vulnerability exists within Adobe Flash Player that allows an attacker to perform remote code execution.

AdobeEPSS 93.1%
CVE-2013-3897KEV
High

A use-after-free vulnerability exists within CDisplayPointer in Microsoft Internet Explorer that allows an attacker to remotely execute arbitrary code.

MicrosoftEPSS 88.2%
CVE-2015-5119KEV
High

A use-after-free vulnerability exists within the ActionScript 3 ByteArray class in Adobe Flash Player that allows an attacker to perform remote code execution.

AdobeEPSS 93.2%
CVE-2002-0367KEV
High

smss.exe debugging subsystem in Microsoft Windows does not properly authenticate programs that connect to other programs, which allows local users to gain administrator or SYSTEM privileges.

MicrosoftEPSS 1.2%