Fixed Intel

CVE Tracker

Track known exploited vulnerabilities, CISA KEV alerts, and linked threat intelligence.

2,234

Total CVEs

1,589

CISA KEV

41

Known Exploits

8.8

Avg CVSS Score

Severity Distribution

CRITICAL 8
HIGH 1599
MEDIUM 7
INFO 620

Showing 20 of 620 CVEs · INFO

CVE-2026-20133KEV
Info

Referenced in article: Cisco Confirms Active Exploitation of Two Catalyst SD-WAN Manager Vulnerabilities

CiscoEPSS 0.1%
CVE-2026-20129
Info

Referenced in article: Cisco Confirms Active Exploitation of Two Catalyst SD-WAN Manager Vulnerabilities

EPSS 0.2%
CVE-2026-20126
Info

Referenced in article: Cisco Confirms Active Exploitation of Two Catalyst SD-WAN Manager Vulnerabilities

EPSS 0.0%
CVE-2026-20122KEV
Info

Referenced in article: Cisco Confirms Active Exploitation of Two Catalyst SD-WAN Manager Vulnerabilities

CiscoEPSS 0.0%
CVE-2023-6895
Info

Referenced in article: Iran-Linked MuddyWater Hackers Target U.S. Networks With New Dindoor Backdoor

EPSS 93.0%
CVE-2026-0667
Info

Referenced in article: Schneider Electric SCADAPack and RemoteConnect

CVE-2025-13957
Info

Referenced in article: Schneider Electric EcoStruxure Data Center Expert

EPSS 0.4%
CVE-2026-22553
Info

Referenced in article: InSAT MasterSCADA BUK-TS

EPSS 1.2%
CVE-2026-27749
Info

Referenced in article: ⚡ Weekly Recap: Qualcomm 0-Day, iOS Exploit Chains, AirSnitch Attack & Vibe-Coded Malware

EPSS 0.1%
CVE-2025-9316
Info

Referenced in article: ⚡ Weekly Recap: Qualcomm 0-Day, iOS Exploit Chains, AirSnitch Attack & Vibe-Coded Malware

EPSS 83.2%
CVE-2026-1492
Info

Referenced in article: ⚡ Weekly Recap: Qualcomm 0-Day, iOS Exploit Chains, AirSnitch Attack & Vibe-Coded Malware

EPSS 29.0%
CVE-2026-3538
Info

Referenced in article: ⚡ Weekly Recap: Qualcomm 0-Day, iOS Exploit Chains, AirSnitch Attack & Vibe-Coded Malware

EPSS 0.1%
CVE-2026-3537
Info

Referenced in article: ⚡ Weekly Recap: Qualcomm 0-Day, iOS Exploit Chains, AirSnitch Attack & Vibe-Coded Malware

EPSS 0.1%
CVE-2026-25611
Info

Referenced in article: ⚡ Weekly Recap: Qualcomm 0-Day, iOS Exploit Chains, AirSnitch Attack & Vibe-Coded Malware

EPSS 0.1%
CVE-2026-3338
Info

Referenced in article: ⚡ Weekly Recap: Qualcomm 0-Day, iOS Exploit Chains, AirSnitch Attack & Vibe-Coded Malware

EPSS 0.0%
CVE-2026-3337
Info

Referenced in article: ⚡ Weekly Recap: Qualcomm 0-Day, iOS Exploit Chains, AirSnitch Attack & Vibe-Coded Malware

EPSS 0.0%
CVE-2025-13476
Info

Referenced in article: ⚡ Weekly Recap: Qualcomm 0-Day, iOS Exploit Chains, AirSnitch Attack & Vibe-Coded Malware

EPSS 0.0%
CVE-2026-23600
Info

A remote authentication bypass vulnerability  exists in HPE AutoPass License Server (APLS).

CVE-2025-14500
Info

IceWarp14 X-File-Operation Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of IceWarp. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of the X-File-Operation header. The issue results from the lack of proper validation of a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code in the context of SYSTEM. Was ZDI-CAN-27394.

CVE-2025-34067
Info

An unauthenticated remote command execution vulnerability exists in the applyCT component of the Hikvision Integrated Security Management Platform due to the use of a vulnerable version of the Fastjson library. The endpoint /bic/ssoService/v1/applyCT deserializes untrusted user input, allowing an attacker to trigger Fastjson's auto-type feature to load arbitrary Java classes. By referencing a malicious class via an LDAP URL, an attacker can achieve remote code execution on the underlying system. Exploitation evidence was observed by the Shadowserver Foundation on 2025-02-05 UTC.