Fixed Intel

CVE Tracker

Track known exploited vulnerabilities, CISA KEV alerts, and linked threat intelligence.

2,235

Total CVEs

1,590

CISA KEV

41

Known Exploits

8.8

Avg CVSS Score

Severity Distribution

CRITICAL 8
HIGH 1600
MEDIUM 7
INFO 620

Showing 20 of 2,235 CVEs

CVE-2016-7201KEV
High

The Chakra JavaScript scripting engine in Microsoft Edge allows remote attackers to execute remote code or cause a denial of service (memory corruption) via a crafted web site.

MicrosoftEPSS 90.1%
CVE-2019-7483KEV
High

In SonicWall SMA100, an unauthenticated Directory Traversal vulnerability in the handleWAFRedirect CGI allows the user to test for the presence of a file on the server.

SonicWallEPSS 42.4%
CVE-2017-0059KEV
High

Microsoft Internet Explorer allow remote attackers to obtain sensitive information from process memory via a crafted web site.

MicrosoftEPSS 85.0%
CVE-2017-0213KEV
High

Microsoft Windows COM Aggregate Marshaler allows for privilege escalation when an attacker runs a specially crafted application.

MicrosoftEPSS 92.7%
CVE-2016-0040KEV
High

The kernel in Microsoft Windows allows local users to gain privileges via a crafted application.

MicrosoftEPSS 78.9%
CVE-2022-26318KEV
High

On WatchGuard Firebox and XTM appliances, an unauthenticated user can execute arbitrary code.

WatchGuardEPSS 92.2%
CVE-2016-11021KEV
High

setSystemCommand on D-Link DCS-930L devices allows a remote attacker to execute code via an OS command.

D-LinkEPSS 91.3%
CVE-2019-0903KEV
High

A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in the memory. An attacker who successfully exploited this vulnerability could take control of the affected system.

MicrosoftEPSS 34.4%
CVE-2012-1823KEV
High

sapi/cgi/cgi_main.c in PHP, when configured as a CGI script, does not properly handle query strings, which allows remote attackers to execute arbitrary code.

PHPCVSS 9.8EPSS 94.4%
Exploit
CVE-2020-2021KEV
High

Palo Alto Networks PAN-OS contains a vulnerability in SAML which allows an attacker to bypass authentication.

Palo Alto NetworksEPSS 21.1%
CVE-2020-25223KEV
High

A remote code execution vulnerability exists in the WebAdmin of Sophos SG UTM.

SophosEPSS 94.4%
CVE-2020-9054KEV
High

Multiple Zyxel network-attached storage (NAS) devices contain a pre-authentication command injection vulnerability, which may allow a remote, unauthenticated attacker to execute arbitrary code.

ZyxelEPSS 94.3%
CVE-2014-6324KEV
High

The Kerberos Key Distribution Center (KDC) in Microsoft allows remote authenticated domain users to obtain domain administrator privileges.

MicrosoftEPSS 89.8%
CVE-2013-5223KEV
High

A cross-site scripting (XSS) vulnerability exists in the D-Link DSL-2760U gateway, allowing remote authenticated users to inject arbitrary web script or HTML.

D-LinkEPSS 35.5%
CVE-2010-4345KEV
High

Exim allows local users to gain privileges by leveraging the ability of the exim user account to specify an alternate configuration file with a directive that contains arbitrary commands.

EximEPSS 4.0%
CVE-2015-1187KEV
High

The ping tool in multiple D-Link and TRENDnet devices allow remote attackers to perform remote code execution.

D-Link and TRENDnetEPSS 81.2%
CVE-2015-3035KEV
High

Directory traversal vulnerability in multiple TP-Link Archer devices allows remote attackers to read arbitrary files via a .. (dot dot) in the PATH_INFO to login/.

TP-LinkEPSS 92.9%
CVE-2016-10174KEV
High

The NETGEAR WNR2000v5 router contains a buffer overflow which can be exploited to achieve remote code execution.

NETGEAREPSS 89.8%
CVE-2013-2251KEV
High

Apache Struts allows remote attackers to execute arbitrary Object-Graph Navigation Language (OGNL) expressions.

ApacheEPSS 94.3%
CVE-2013-4810KEV
High

HP ProCurve Manager (PCM), PCM+, Identity Driven Manager (IDM), and Application Lifecycle Management allow remote attackers to execute arbitrary code via a marshalled object to (1) EJBInvokerServlet or (2) JMXInvokerServlet.

Hewlett Packard (HP)EPSS 89.6%