Fixed Intel

CVE Tracker

Track known exploited vulnerabilities, CISA KEV alerts, and linked threat intelligence.

2,235

Total CVEs

1,590

CISA KEV

41

Known Exploits

8.8

Avg CVSS Score

Severity Distribution

CRITICAL 8
HIGH 1600
MEDIUM 7
INFO 620

Showing 20 of 1,600 CVEs · HIGH

CVE-2020-8816KEV
High

Pi-hole Web v4.3.2 (aka AdminLTE) allows Remote Code Execution by privileged dashboard users via a crafted DHCP static lease.

Pi-holeEPSS 90.8%
CVE-2020-17463KEV
High

FUEL CMS 1.4.7 allows SQL Injection via the col parameter to /pages/items, /permissions/items, or /navigation/items.

Fuel CMSEPSS 15.3%
CVE-2021-35394KEV
High

RealTek Jungle SDK contains multiple memory corruption vulnerabilities which can allow an attacker to perform remote code execution.

RealtekEPSS 93.8%
CVE-2021-44228KEV
High

Apache Log4j2 contains a vulnerability where JNDI features do not protect against attacker-controlled JNDI-related endpoints, allowing for remote code execution.

ApacheEPSS 94.4%
CVE-2021-37415KEV
High

Zoho ManageEngine ServiceDesk Plus before 11302 is vulnerable to authentication bypass that allows a few REST-API URLs without authentication

ZohoEPSS 92.0%
CVE-2021-44077KEV
High

Zoho ManageEngine ServiceDesk Plus before 11306, ServiceDesk Plus MSP before 10530, and SupportCenter Plus before 11014 are vulnerable to unauthenticated remote code execution

ZohoEPSS 94.3%
CVE-2020-11261KEV
High

Memory corruption due to improper check to return error when user application requests memory allocation of a huge size in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables

QualcommEPSS 1.1%
CVE-2018-14847KEV
High

MikroTik RouterOS through 6.42 allows unauthenticated remote attackers to read arbitrary files and remote authenticated attackers to write arbitrary files due to a directory traversal vulnerability in the WinBox interface.

MikroTikEPSS 92.8%
CVE-2021-40438KEV
High

A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. This issue affects Apache HTTP Server 2.4.48 and earlier.

ApacheEPSS 94.4%
CVE-2021-22204KEV
High

Improper neutralization of user data in the DjVu file format in Exiftool versions 7.44 and up allows arbitrary code execution when parsing the malicious image

PerlEPSS 92.8%
CVE-2021-42292KEV
High

A security feature bypass vulnerability in Microsoft Excel would allow a local user to perform arbitrary code execution.

MicrosoftEPSS 19.1%
CVE-2021-40449KEV
High

Unspecified vulnerability allows for an authenticated user to escalate privileges.

MicrosoftEPSS 91.1%
CVE-2021-42321KEV
High

An authenticated attacker could leverage improper validation in cmdlet arguments within Microsoft Exchange and perform remote code execution.

MicrosoftEPSS 93.4%
CVE-2020-11652KEV
High

SaltStack Salt contains a path traversal vulnerability in the salt-master process ClearFuncs which allows directory access to authenticated users. Salt users who follow fundamental internet security guidelines and best practices are not affected by this vulnerability.

SaltStackEPSS 94.3%
CVE-2017-16651KEV
High

Roundcube Webmail contains a file disclosure vulnerability caused by insufficient input validation in conjunction with file-based attachment plugins, which are used by default.

RoundcubeEPSS 37.8%
CVE-2020-10181KEV
High

Sumavision Enhanced Multimedia Router (EMR) contains a cross-site request forgery (CSRF) vulnerability allowing the creation of users with elevated privileges as administrator on a device.

SumavisionEPSS 20.6%
CVE-2021-31755KEV
High

Tenda AC11 devices contain a stack buffer overflow vulnerability in /goform/setmac which allows attackers to execute code via a crafted post request.

TendaEPSS 94.3%
CVE-2021-20016KEV
High

SonicWall SSLVPN SMA100 contains a SQL injection vulnerability that allows remote exploitation for credential access by an unauthenticated attacker.

SonicWallEPSS 78.0%
CVE-2017-9248KEV
High

Progress Telerik UI for ASP.NET AJAX and Sitefinity have a cryptographic weakness in Telerik.Web.UI.dll that can be exploited to disclose encryption keys (Telerik.Web.UI.DialogParametersEncryptionKey and/or the MachineKey), perform cross-site-scripting (XSS) attacks, compromise the ASP.NET ViewState, and/or upload and download files.

ProgressEPSS 87.8%
CVE-2018-20062KEV
High

ThinkPHP "noneCms" contains an unspecified vulnerability that allows for remote code execution through crafted use of the filter parameter.

ThinkPHPEPSS 94.3%