Fixed Intel

CVE Tracker

Track known exploited vulnerabilities, CISA KEV alerts, and linked threat intelligence.

2,235

Total CVEs

1,590

CISA KEV

41

Known Exploits

8.8

Avg CVSS Score

Severity Distribution

CRITICAL 8
HIGH 1600
MEDIUM 7
INFO 620

Showing 20 of 2,235 CVEs

CVE-2020-16009KEV
High

Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

GoogleEPSS 84.4%
CVE-2019-11580KEV
High

Atlassian Crowd and Crowd Data Center contain a remote code execution vulnerability resulting from a pdkinstall development plugin being incorrectly enabled in release builds.

AtlassianEPSS 94.4%
CVE-2020-3580KEV
High

Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) contain an insufficient input validation vulnerability for user-supplied input by the web services interface. Successful exploitation could allow an attacker to perform cross-site scripting (XSS) in the context of the interface or access sensitive browser-based information.

CiscoEPSS 92.6%
CVE-2017-9822KEV
High

DotNetNuke (DNN) contains a vulnerability that may allow for remote code execution via cookie deserialization.

DotNetNuke (DNN)CVSS 8.8EPSS 94.3%
Exploit
CVE-2020-25506KEV
High

D-Link DNS-320 device contains a command injection vulnerability in the sytem_mgr.cgi component that may allow for remote code execution.

D-LinkEPSS 94.3%
CVE-2018-15811KEV
High

DotNetNuke (DNN) contains an inadequate encryption strength vulnerability resulting from the use of a weak encryption algorithm to protect input parameters.

DotNetNuke (DNN)EPSS 93.0%
CVE-2020-8657KEV
High

EyesOfNetwork contains a use of hard-coded credentials vulnerability, as it uses the same API key by default. Exploitation allows an attacker to calculate or guess the admin access token.

EyesOfNetworkEPSS 90.3%
CVE-2020-8515KEV
High

DrayTek Vigor3900, Vigor2960, and Vigor300B routers contain an unspecified vulnerability that allows for remote code execution.

DrayTekEPSS 94.4%
CVE-2018-6789KEV
High

Exim contains a buffer overflow vulnerability in the base64d function part of the SMTP listener that may allow for remote code execution.

EximEPSS 86.4%
CVE-2020-26919KEV
High

Netgear JGS516PE devices contain a missing function level access control vulnerability.

NETGEAREPSS 94.2%
CVE-2019-9082KEV
High

ThinkPHP contains an unspecified vulnerability that allows for remote code execution via public//?s=index/\think\app/invokefunction&function=call_user_func_array&vars[0]=system&vars[1][]= followed by the command.

ThinkPHPCVSS 8.8EPSS 94.3%
Exploit
CVE-2021-1497KEV
High

Cisco HyperFlex HX Installer Virtual Machine contains an insufficient input validation vulnerability which could allow an attacker to execute commands on an affected device as the root user.

CiscoCVSS 9.8EPSS 94.4%
Exploit
CVE-2021-35464KEV
High

ForgeRock Access Management (AM) Core Server allows an attacker who sends a specially crafted HTTP request to one of three endpoints (/ccversion/Version, /ccversion/Masthead, or /ccversion/ButtonFrame) to execute code in the context of the current user (unless ForgeRock AM is running as root user, which the vendor does not recommend).

ForgeRockCVSS 9.8EPSS 94.4%
Exploit
CVE-2019-16759KEV
High

The PHP module within vBulletin contains an unspecified vulnerability that allows for remote code execution via the widgetConfig[code] parameter in an ajax/render/widget_php routestring request.

vBulletinCVSS 9.8EPSS 94.4%
Exploit
CVE-2020-14882KEV
High

Oracle WebLogic Server contains an unspecified vulnerability, which is assessed to allow for remote code execution, based on this vulnerability being related to CVE-2020-14750.

oracleCVSS 9.8EPSS 94.5%
Exploit
CVE-2021-22005KEV
High

VMware vCenter Server contains a file upload vulnerability in the Analytics service that allows a user with network access to port 443 to execute code.

VMwareCVSS 9.8EPSS 94.5%
Exploit
CVE-2019-11510KEV
High

Ivanti Pulse Connect Secure contains an arbitrary file read vulnerability that allows an unauthenticated remote attacker with network access via HTTPS to send a specially crafted URI.

IvantiCVSS 10EPSS 94.5%
Exploit
CVE-2019-3396KEV
High

Atlassian Confluence Server and Data Center contain a server-side template injection vulnerability that may allow an attacker to achieve path traversal and remote code execution.

AtlassianCVSS 9.8EPSS 94.5%
Exploit
CVE-2019-17558KEV
High

The Apache Solr VelocityResponseWriter plug-in contains an unspecified vulnerability which can allow for remote code execution.

ApacheCVSS 7.5EPSS 94.5%
Exploit
CVE-2018-7600KEV
High

Drupal Core contains a remote code execution vulnerability that could allow an attacker to exploit multiple attack vectors on a Drupal site, resulting in complete site compromise.

DrupalCVSS 9.8EPSS 94.5%
Exploit