Fixed Intel

CVE Tracker

Track known exploited vulnerabilities, CISA KEV alerts, and linked threat intelligence.

2,235

Total CVEs

1,590

CISA KEV

41

Known Exploits

8.8

Avg CVSS Score

Severity Distribution

CRITICAL 8
HIGH 1600
MEDIUM 7
INFO 620

Showing 20 of 1,600 CVEs · HIGH

CVE-2013-3896KEV
High

Microsoft Silverlight does not properly validate pointers during access to Silverlight elements, which allows remote attackers to obtain sensitive information via a crafted Silverlight application.

MicrosoftEPSS 81.6%
CVE-2014-2817KEV
High

Microsoft Internet Explorer cotains an unspecified vulnerability that allows remote attackers to gain privileges via a crafted web site.

MicrosoftEPSS 26.4%
CVE-2013-0422KEV
High

A vulnerability in the way Java restricts the permissions of Java applets could allow an attacker to execute commands on a vulnerable system.

OracleEPSS 93.8%
CVE-2013-3993KEV
High

Certain APIs within BigInsights can take invalid input that might allow attackers unauthorized access to read, write, modify, or delete data.

IBMEPSS 21.0%
CVE-2010-0840KEV
High

Unspecified vulnerability in the Java Runtime Environment (JRE) in Java SE component allows remote attackers to affect confidentiality, integrity, and availability via Unknown vectors.

OracleEPSS 92.1%
CVE-2015-1769KEV
High

A privilege escalation vulnerability exists when the Windows Mount Manager component improperly processes symbolic links.

MicrosoftEPSS 31.8%
CVE-2015-1671KEV
High

A remote code execution vulnerability exists when components of Windows, .NET Framework, Office, Lync, and Silverlight fail to properly handle TrueType fonts.

MicrosoftEPSS 85.9%
CVE-2014-0546KEV
High

Adobe Reader and Acrobat on Windows allow attackers to bypass a sandbox protection mechanism, and consequently execute native code in a privileged context.

AdobeEPSS 29.7%
CVE-2015-2360KEV
High

Win32k.sys in the kernel-mode drivers in Microsoft Windows allows local users to gain privileges or cause denial-of-service (DoS).

MicrosoftEPSS 13.2%
CVE-2014-4123KEV
High

Microsoft Internet Explorer contains an unspecified vulnerability that allows remote attackers to gain privileges via a crafted web site.

MicrosoftEPSS 53.6%
CVE-2014-3153KEV
High

The futex_requeue function in kernel/futex.c in Linux kernel does not ensure that calls have two different futex addresses, which allows local users to gain privileges.

LinuxEPSS 68.9%
CVE-2015-6175KEV
High

The kernel in Microsoft Windows contains a vulnerability that allows local users to gain privileges via a crafted application.

MicrosoftEPSS 2.8%
CVE-2019-3010KEV
High

Oracle Solaris component: XScreenSaver contains an unspecified vulnerability that allows for privilege escalation.

OracleEPSS 47.1%
CVE-2015-8651KEV
High

Integer overflow in Adobe Flash Player allows attackers to execute code.

AdobeEPSS 89.0%
CVE-2016-7256KEV
High

A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts. An attacker who successfully exploits this vulnerability could take control of the affected system.

MicrosoftEPSS 65.1%
CVE-2016-3393KEV
High

A remote code execution vulnerability exists due to the way the Windows GDI component handles objects in the memory. An attacker who successfully exploits this vulnerability could take control of the affected system.

MicrosoftEPSS 40.8%
CVE-2016-0034KEV
High

Microsoft Silverlight mishandles negative offsets during decoding, which allows attackers to execute remote code or cause a denial-of-service (DoS).

MicrosoftEPSS 40.5%
CVE-2018-19949KEV
High

A command injection vulnerability affecting QNAP NAS File Station could allow remote attackers to run commands.

QNAPEPSS 44.2%
CVE-2016-6366KEV
High

A buffer overflow vulnerability in the Simple Network Management Protocol (SNMP) code of Cisco ASA software could allow an attacker to cause a reload of the affected system or to remotely execute code.

CiscoEPSS 91.4%
CVE-2018-19943KEV
High

A cross-site scripting vulnerability affecting QNAP NAS File Station could allow remote attackers to inject malicious code.

QNAPEPSS 5.5%