Fixed Intel

CVE Tracker

Track known exploited vulnerabilities, CISA KEV alerts, and linked threat intelligence.

2,235

Total CVEs

1,590

CISA KEV

41

Known Exploits

8.8

Avg CVSS Score

Severity Distribution

CRITICAL 8
HIGH 1600
MEDIUM 7
INFO 620

Showing 20 of 1,600 CVEs · HIGH

CVE-2012-2539KEV
High

Microsoft Word allows attackers to execute remote code or cause a denial-of-service (DoS) via crafted RTF data.

MicrosoftEPSS 84.4%
CVE-2021-38646KEV
High

Microsoft Office Access Connectivity Engine contains an unspecified vulnerability which can allow for remote code execution.

MicrosoftEPSS 42.7%
CVE-2016-0151KEV
High

The Client-Server Run-time Subsystem (CSRSS) in Microsoft mismanages process tokens, which allows local users to gain privileges via a crafted application.

MicrosoftEPSS 44.1%
CVE-2018-8406KEV
High

An elevation of privilege vulnerability exists when the DirectX Graphics Kernel (DXGKRNL) driver improperly handles objects in memory.

MicrosoftEPSS 50.0%
CVE-2022-1096KEV
High

Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

GoogleEPSS 47.3%
CVE-2021-26085KEV
High

Affected versions of Atlassian Confluence Server allow remote attackers to view restricted resources via a pre-authorization arbitrary file read vulnerability in the /s/ endpoint.

AtlassianEPSS 94.0%
CVE-2016-7200KEV
High

The Chakra JavaScript scripting engine in Microsoft Edge allows remote attackers to execute remote code or cause a denial of service (memory corruption) via a crafted web site.

MicrosoftEPSS 89.2%
CVE-2015-2426KEV
High

A remote code execution vulnerability exists in Microsoft Windows when the Windows Adobe Type Manager Library improperly handles specially crafted OpenType fonts.

MicrosoftEPSS 91.8%
CVE-2012-2034KEV
High

Adobe Flash Player contains a memory corruption vulnerability that allows for remote code execution or denial-of-service (DoS).

AdobeEPSS 10.7%
CVE-2010-4398KEV
High

Stack-based buffer overflow in the RtlQueryRegistryValues function in win32k.sys in Microsoft Windows allows local users to gain privileges, and bypass the User Account Control (UAC) feature.

MicrosoftEPSS 6.4%
CVE-2014-6287KEV
High

The findMacroMarker function in parserLib.pas in Rejetto HTTP File Server (HFS or HttpFileServer) allows remote attackers to execute arbitrary programs.

RejettoEPSS 94.4%
CVE-2010-4344KEV
High

Heap-based buffer overflow in the string_vformat function in string.c in Exim before 4.70 allows remote attackers to execute arbitrary code via an SMTP session.

EximEPSS 61.5%
CVE-2016-1555KEV
High

Multiple NETGEAR Wireless Access Point devices allows unauthenticated web pages to pass form input directly to the command-line interface. Exploitation allows for arbitrary code execution.

NETGEAREPSS 94.3%
CVE-2014-3120KEV
High

Elasticsearch enables dynamic scripting, which allows remote attackers to execute arbitrary MVEL expressions and Java code.

ElasticEPSS 85.6%
CVE-2010-2861KEV
High

A directory traversal vulnerability exists in the administrator console in Adobe ColdFusion which allows remote attackers to read arbitrary files.

AdobeEPSS 94.3%
CVE-2014-6332KEV
High

OleAut32.dll in OLE in Microsoft Windows allows remote attackers to remotely execute code via a crafted web site.

MicrosoftEPSS 94.1%
CVE-2010-3035KEV
High

Cisco IOS XR, when BGP is the configured routing feature, allows remote attackers to cause a denial-of-service (DoS).

CiscoEPSS 3.2%
CVE-2013-4810KEV
High

HP ProCurve Manager (PCM), PCM+, Identity Driven Manager (IDM), and Application Lifecycle Management allow remote attackers to execute arbitrary code via a marshalled object to (1) EJBInvokerServlet or (2) JMXInvokerServlet.

Hewlett Packard (HP)EPSS 89.6%
CVE-2010-4345KEV
High

Exim allows local users to gain privileges by leveraging the ability of the exim user account to specify an alternate configuration file with a directive that contains arbitrary commands.

EximEPSS 4.0%
CVE-2013-2251KEV
High

Apache Struts allows remote attackers to execute arbitrary Object-Graph Navigation Language (OGNL) expressions.

ApacheEPSS 94.3%