Fixed Intel

CVE Tracker

Track known exploited vulnerabilities, CISA KEV alerts, and linked threat intelligence.

2,235

Total CVEs

1,590

CISA KEV

41

Known Exploits

8.8

Avg CVSS Score

Severity Distribution

CRITICAL 8
HIGH 1600
MEDIUM 7
INFO 620

Showing 20 of 1,600 CVEs · HIGH

CVE-2020-8657KEV
High

EyesOfNetwork contains a use of hard-coded credentials vulnerability, as it uses the same API key by default. Exploitation allows an attacker to calculate or guess the admin access token.

EyesOfNetworkEPSS 90.3%
CVE-2018-15811KEV
High

DotNetNuke (DNN) contains an inadequate encryption strength vulnerability resulting from the use of a weak encryption algorithm to protect input parameters.

DotNetNuke (DNN)EPSS 93.0%
CVE-2020-5735KEV
High

Amcrest cameras and NVR contain a stack-based buffer overflow vulnerability through port 37777 that allows an unauthenticated, remote attacker to crash the device and possibly execute code.

AmcrestEPSS 61.6%
CVE-2020-25506KEV
High

D-Link DNS-320 device contains a command injection vulnerability in the sytem_mgr.cgi component that may allow for remote code execution.

D-LinkEPSS 94.3%
CVE-2017-9822KEV
High

DotNetNuke (DNN) contains a vulnerability that may allow for remote code execution via cookie deserialization.

DotNetNuke (DNN)CVSS 8.8EPSS 94.3%
Exploit
CVE-2018-15961KEV
High

Adobe ColdFusion contains an unrestricted file upload vulnerability that could allow for code execution.

AdobeEPSS 94.4%
CVE-2020-0041KEV
High

Android Kernel binder_transaction of binder.c contains an out-of-bounds write vulnerability due to an incorrect bounds check that could allow for local privilege escalation. This vulnerability was observed chained with CVE-2019-2215 and CVE-2020-0069 under exploit chain "AbstractEmu."

AndroidEPSS 23.9%
CVE-2021-26858KEV
High

Microsoft Exchange Server contains an unspecified vulnerability that allows for remote code execution. This vulnerability is part of the ProxyLogon exploit chain.

MicrosoftEPSS 53.0%
CVE-2021-21017KEV
High

Acrobat Acrobat and Reader contain a heap-based buffer overflow vulnerability that could allow an unauthenticated attacker to achieve code execution in the context of the current user.

AdobeEPSS 90.6%
CVE-2020-3580KEV
High

Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) contain an insufficient input validation vulnerability for user-supplied input by the web services interface. Successful exploitation could allow an attacker to perform cross-site scripting (XSS) in the context of the interface or access sensitive browser-based information.

CiscoEPSS 92.6%
CVE-2021-27104KEV
High

Accellion FTA contains an OS command injection vulnerability exploited via a crafted POST request to various admin endpoints.

AccellionEPSS 6.0%
CVE-2021-22893KEV
High

Ivanti Pulse Connect Secure contains a use-after-free vulnerability that allow a remote, unauthenticated attacker to execute code via license services.

IvantiEPSS 93.6%
CVE-2018-11776KEV
High

Apache Struts contains a vulnerability that allows for remote code execution under two circumstances. One, where the alwaysSelectFullNamespace option is true and the value isn't set for a result defined in underlying configurations and in same time, its upper package configuration have no or wildcard namespace. Or, using URL tag which doesn't have value and action set and in same time, its upper package configuration have no or wildcard namespace.

ApacheEPSS 94.4%
CVE-2020-0069KEV
High

Multiple MediaTek chipsets contain an insufficient input validation vulnerability and have missing SELinux restrictions in the Command Queue drivers ioctl handlers. This causes an out-of-bounds write leading to privilege escalation. This vulnerability was observed chained with CVE-2019-2215 and CVE-2020-0041 under exploit chain "AbstractEmu."

MediaTekEPSS 0.7%
CVE-2021-27103KEV
High

Accellion FTA contains a server-side request forgery (SSRF) vulnerability exploited via a crafted POST request to wmProgressstat.html.

AccellionEPSS 2.9%
CVE-2021-27101KEV
High

Accellion FTA contains a SQL injection vulnerability exploited via a crafted host header in a request to document_root.html.

AccellionEPSS 0.8%
CVE-2018-4939KEV
High

Adobe ColdFusion contains a deserialization of untrusted data vulnerability that could allow for code execution.

AdobeEPSS 76.8%
CVE-2021-27065KEV
High

Microsoft Exchange Server contains an unspecified vulnerability that allows for remote code execution. This vulnerability is part of the ProxyLogon exploit chain.

MicrosoftEPSS 94.3%
CVE-2021-36741KEV
High

Trend Micro Apex One, Apex One as a Service, and Worry-Free Business Security contain an improper input validation vulnerability that allows a remote attacker to upload files.

Trend MicroEPSS 0.6%
CVE-2020-17144KEV
High

Microsoft Exchange Server improperly validates cmdlet arguments which allow an attacker to perform remote code execution.

MicrosoftEPSS 92.7%