Fixed Intel

CVE Tracker

Track known exploited vulnerabilities, CISA KEV alerts, and linked threat intelligence.

1,542

Total CVEs

1,542

CISA KEV

35

Known Exploits

9.3

Avg CVSS Score

Severity Distribution

HIGH 1542

Showing 20 of 1,542 CVEs · HIGH

CVE-2021-28663KEV
High

Arm Mali Graphics Processing Unit (GPU) kernel driver contains a use-after-free vulnerability that may allow a non-privileged user to make improper operations on GPU memory to gain root privilege, and/or disclose information.

ArmEPSS 2.4%
CVE-2020-9859KEV
High

Apple iOS, iPadOS, macOS, watchOS, and tvOS contain an unspecified vulnerability that may allow an application to execute code with kernel privileges.

AppleEPSS 0.1%
CVE-2021-27562KEV
High

Arm Trusted Firmware contains an out-of-bounds write vulnerability allowing the non-secure (NS) world to trigger a system halt, overwrite secure data, or print out secure data when calling secure functions under the non-secure processing environment (NSPE) handler mode. This vulnerability affects Yealink Device Management servers.

ArmEPSS 47.9%
CVE-2019-0211KEV
High

Apache HTTP Server, with MPM event, worker or prefork, code executing in less-privileged child processes or threads (including scripts executed by an in-process scripting interpreter) could execute code with the privileges of the parent process (usually root) by manipulating the scoreboard.

ApacheEPSS 89.5%
CVE-2019-11580KEV
High

Atlassian Crowd and Crowd Data Center contain a remote code execution vulnerability resulting from a pdkinstall development plugin being incorrectly enabled in release builds.

AtlassianEPSS 94.4%
CVE-2021-26084KEV
High

Atlassian Confluence Server and Data Server contain an Object-Graph Navigation Language (OGNL) injection vulnerability that may allow an unauthenticated attacker to execute code.

AtlassianEPSS 94.4%
CVE-2016-4437KEV
High

Apache Shiro contains a vulnerability which may allow remote attackers to execute code or bypass intended access restrictions via an unspecified request parameter when a cipher key has not been configured for the "remember me" feature.

ApacheEPSS 94.2%
CVE-2021-42013KEV
High

Apache HTTP Server contains a path traversal vulnerability that allows an attacker to perform remote code execution if files outside directories configured by Alias-like directives are not under default require all denied or if CGI scripts are enabled. This CVE ID resolves an incomplete patch for CVE-2021-41773.

ApacheEPSS 94.4%
CVE-2020-10148KEV
High

SolarWinds Orion API contains an authentication bypass vulnerability that could allow a remote attacker to execute API commands.

SolarWindsEPSS 94.3%
CVE-2021-28664KEV
High

Arm Mali Graphics Processing Unit (GPU) kernel driver contains an unspecified vulnerability that may allow a non-privileged user to gain write access to read-only memory, gain root privilege, corrupt memory, and modify the memory of other processes.

ArmEPSS 0.1%
CVE-2018-4878KEV
High

Adobe Flash Player contains a use-after-free vulnerability that could allow for code execution.

AdobeEPSS 93.3%
CVE-2021-28550KEV
High

Adobe Acrobat and Reader contains a use-after-free vulnerability that could allow an unauthenticated attacker to achieve code execution in the context of the current user.

AdobeEPSS 32.1%
CVE-2019-2215KEV
High

Android Kernel contains a use-after-free vulnerability in binder.c that allows for privilege escalation from an application to the Linux Kernel. This vulnerability was observed chained with CVE-2020-0041 and CVE-2020-0069 under exploit chain "AbstractEmu."

AndroidEPSS 52.9%
CVE-2021-20090KEV
High

Arcadyan Buffalo firmware contains a path traversal vulnerability that could allow unauthenticated, remote attackers to bypass authentication and access sensitive information. This vulnerability affects multiple routers across several different vendors.

ArcadyanEPSS 94.4%
CVE-2020-5735KEV
High

Amcrest cameras and NVR contain a stack-based buffer overflow vulnerability through port 37777 that allows an unauthenticated, remote attacker to crash the device and possibly execute code.

AmcrestEPSS 61.6%
CVE-2018-15961KEV
High

Adobe ColdFusion contains an unrestricted file upload vulnerability that could allow for code execution.

AdobeEPSS 94.4%
CVE-2019-16256KEV
High

SIMalliance Toolbox Browser contains an command injection vulnerability that could allow remote attackers to retrieve location and IMEI information or execute a range of other attacks by modifying the attack message.

SIMallianceEPSS 61.2%
CVE-2017-9805KEV
High

Apache Struts REST Plugin uses an XStreamHandler with an instance of XStream for deserialization without any type filtering, which can lead to remote code execution when deserializing XML payloads.

ApacheEPSS 94.3%
CVE-2020-0041KEV
High

Android Kernel binder_transaction of binder.c contains an out-of-bounds write vulnerability due to an incorrect bounds check that could allow for local privilege escalation. This vulnerability was observed chained with CVE-2019-2215 and CVE-2020-0069 under exploit chain "AbstractEmu."

AndroidEPSS 23.9%
CVE-2021-40539KEV
High

Zoho ManageEngine ADSelfService Plus contains an authentication bypass vulnerability affecting the REST API URLs which allow for remote code execution.

ZohoEPSS 94.4%