Fixed Intel

CVE Tracker

Track known exploited vulnerabilities, CISA KEV alerts, and linked threat intelligence.

2,235

Total CVEs

1,590

CISA KEV

41

Known Exploits

8.8

Avg CVSS Score

Severity Distribution

CRITICAL 8
HIGH 1600
MEDIUM 7
INFO 620

Showing 20 of 1,600 CVEs · HIGH

CVE-2020-6820KEV
High

Mozilla Firefox and Thunderbird contain a race condition vulnerability when handling a ReadableStream under certain conditions. The race condition creates a use-after-free vulnerability, causing unspecified impacts.

MozillaEPSS 5.0%
CVE-2020-0646KEV
High

Microsoft .NET Framework contains an improper input validation vulnerability that allows for remote code execution.

MicrosoftEPSS 93.9%
CVE-2019-0808KEV
High

Microsoft Win32k contains a privilege escalation vulnerability due to the component failing to properly handle objects in memory. Successful exploitation allows an attacker to run code in kernel mode.

MicrosoftEPSS 74.2%
CVE-2021-1905KEV
High

Multiple Qualcomm Chipsets contain a use after free vulnerability due to improper handling of memory mapping of multiple processes simultaneously.

QualcommEPSS 1.1%
CVE-2019-1214KEV
High

Microsoft Windows Common Log File System (CLFS) driver improperly handles objects in memory which can allow for privilege escalation.

MicrosoftEPSS 3.7%
CVE-2021-38648KEV
High

Microsoft Open Management Infrastructure (OMI) within Azure VM Management Extensions contains an unspecified vulnerability allowing privilege escalation.

MicrosoftEPSS 31.8%
CVE-2019-15949KEV
High

Nagios XI contains a remote code execution vulnerability in which a user can modify the check_plugin executable and insert malicious commands to execute as root.

NagiosEPSS 87.1%
CVE-2019-17026KEV
High

Mozilla Firefox and Thunderbird contain a type confusion vulnerability due to incorrect alias information in the IonMonkey JIT compiler when setting array elements.

MozillaEPSS 64.8%
CVE-2020-1147KEV
High

Microsoft .NET Framework, Microsoft SharePoint, and Visual Studio contain a remote code execution vulnerability when the software fails to check the source markup of XML file input. Successful exploitation allows an attacker to execute code in the context of the process responsible for deserialization of the XML content.

MicrosoftEPSS 93.4%
CVE-2021-36955KEV
High

Microsoft Windows Common Log File System (CLFS) driver contains an unspecified vulnerability that allows for privilege escalation.

MicrosoftEPSS 20.6%
CVE-2020-2555KEV
High

Multiple Oracle products contain a remote code execution vulnerability that allows an unauthenticated attacker with network access via T3 or HTTP to takeover the affected system. Impacted Oracle products: Oracle Coherence in Fusion Middleware, Oracle Utilities Framework, Oracle Retail Assortment Planning, Oracle Commerce, Oracle Communications Diameter Signaling Router (DSR).

OracleEPSS 93.1%
CVE-2019-19356KEV
High

Netis WF2419 devices contains an unspecified vulnerability that allows an attacker to perform remote code execution as root through the router's web management page.

NetisEPSS 91.1%
CVE-2021-22894KEV
High

Ivanti Pulse Connect Secure Collaboration Suite contains a buffer overflow vulnerabilities that allows a remote authenticated users to execute code as the root user via maliciously crafted meeting room.

IvantiEPSS 25.7%
CVE-2012-3152KEV
High

Oracle Fusion Middleware Reports Developer contains an unspecified vulnerability that allows remote attackers to affect confidentiality and integrity of affected systems.

OracleEPSS 93.5%
CVE-2020-14750KEV
High

Oracle WebLogic Server contains an unspecified vulnerability allowing an unauthenticated attacker to perform remote code execution. This vulnerability is related to CVE-2020-14882.

OracleEPSS 94.4%
CVE-2021-22899KEV
High

Ivanti Pulse Connect Secure contains a command injection vulnerability that allows remote authenticated users to perform remote code execution via Windows File Resource Profiles.

IvantiEPSS 16.6%
CVE-2020-14871KEV
High

Oracle Solaris and Oracle ZFS Storage Appliance Kit contain an unspecified vulnerability causing high impacts to confidentiality, integrity, and availability of affected systems.

OracleEPSS 88.9%
CVE-2021-22900KEV
High

Ivanti Pulse Connect Secure contains an unrestricted file upload vulnerability that allows an authenticated administrator to perform a file write via a maliciously crafted archive upload in the administrator web interface.

IvantiEPSS 0.8%
CVE-2020-8243KEV
High

Ivanti Pulse Connect Secure contains an unspecified vulnerability in the admin web interface that could allow an authenticated attacker to upload a custom template to perform code execution.

IvantiEPSS 20.5%
CVE-2020-8644KEV
High

PlaySMS contains a server-side template injection vulnerability that allows for remote code execution.

PlaySMSEPSS 94.0%