Fixed Intel

CVE Tracker

Track known exploited vulnerabilities, CISA KEV alerts, and linked threat intelligence.

2,235

Total CVEs

1,590

CISA KEV

41

Known Exploits

8.8

Avg CVSS Score

Severity Distribution

CRITICAL 8
HIGH 1600
MEDIUM 7
INFO 620

Showing 20 of 2,235 CVEs

CVE-2017-8543KEV
High

Microsoft Windows allows an attacker to take control of the affected system when Windows Search fails to handle objects in memory.

MicrosoftEPSS 83.8%
CVE-2017-18362KEV
High

ConnectWise ManagedITSync integration for Kaseya VSA is vulnerable to unauthenticated remote commands that allow full direct access to the Kaseya VSA database.

KaseyaEPSS 80.3%
CVE-2016-4656KEV
High

A memory corruption vulnerability in Apple iOS kernel allows attackers to execute code in a privileged context or cause a denial-of-service (DoS) via a crafted application.

AppleEPSS 66.7%
CVE-2016-6367KEV
High

A vulnerability in the command-line interface (CLI) parser of Cisco ASA software could allow an authenticated, local attacker to create a denial-of-service (DoS) condition or potentially execute code.

CiscoEPSS 23.1%
CVE-2018-19943KEV
High

A cross-site scripting vulnerability affecting QNAP NAS File Station could allow remote attackers to inject malicious code.

QNAPEPSS 5.5%
CVE-2016-6366KEV
High

A buffer overflow vulnerability in the Simple Network Management Protocol (SNMP) code of Cisco ASA software could allow an attacker to cause a reload of the affected system or to remotely execute code.

CiscoEPSS 91.4%
CVE-2018-19949KEV
High

A command injection vulnerability affecting QNAP NAS File Station could allow remote attackers to run commands.

QNAPEPSS 44.2%
CVE-2018-19953KEV
High

A cross-site scripting vulnerability affecting QNAP NAS File Station could allow remote attackers to inject malicious code.

QNAPEPSS 31.5%
CVE-2017-0147KEV
High

The SMBv1 server in Microsoft Windows allows remote attackers to obtain sensitive information from process memory via a crafted packet.

MicrosoftEPSS 92.4%
CVE-2016-4657KEV
High

Apple iOS WebKit contains a memory corruption vulnerability that allows attackers to execute remote code or cause a denial-of-service (DoS) via a crafted web site. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing.

AppleEPSS 78.4%
CVE-2017-0149KEV
High

Microsoft Internet Explorer contains a memory corruption vulnerability that allows remote attackers to execute code or cause a denial-of-service (DoS) via a crafted website.

MicrosoftEPSS 41.5%
CVE-2018-8611KEV
High

A privilege escalation vulnerability exists when the Windows kernel fails to properly handle objects in memory.

MicrosoftEPSS 16.4%
CVE-2018-8589KEV
High

A privilege escalation vulnerability exists when Windows improperly handles calls to Win32k.sys. An attacker who successfully exploited this vulnerability could run remote code in the security context of the local system.

MicrosoftEPSS 46.3%
CVE-2020-1027KEV
High

An elevation of privilege vulnerability exists in the way that the Windows Kernel handles objects in memory. An attacker who successfully exploited the vulnerability could execute code with elevated permissions.

MicrosoftEPSS 11.9%
CVE-2021-1048KEV
High

Android kernel contains a use-after-free vulnerability that allows for privilege escalation.

AndroidEPSS 1.7%
CVE-2021-0920KEV
High

Android kernel contains a race condition, which allows for a use-after-free vulnerability. Exploitation can allow for privilege escalation.

AndroidEPSS 0.9%
CVE-2019-18426KEV
High

A vulnerability in WhatsApp Desktop when paired with WhatsApp for iPhone allows cross-site scripting and local file reading.

Meta PlatformsEPSS 55.3%
CVE-2019-1130KEV
High

A privilege escalation vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard links.

MicrosoftEPSS 1.9%
CVE-2019-1385KEV
High

A privilege escalation vulnerability exists when the Windows AppX Deployment Extensions improperly performs privilege management, resulting in access to system files.

MicrosoftEPSS 0.4%
CVE-2018-5002KEV
High

Adobe Flash Player have a stack-based buffer overflow vulnerability that could lead to remote code execution.

AdobeEPSS 45.0%