Fixed Intel

CVE Tracker

Track known exploited vulnerabilities, CISA KEV alerts, and linked threat intelligence.

2,235

Total CVEs

1,590

CISA KEV

41

Known Exploits

8.8

Avg CVSS Score

Severity Distribution

CRITICAL 8
HIGH 1600
MEDIUM 7
INFO 620

Showing 20 of 2,235 CVEs

CVE-2018-0125KEV
High

A vulnerability in the web interface of the Cisco VPN Routers could allow an unauthenticated, remote attacker to execute arbitrary code as root and gain full control of an affected system.

CiscoEPSS 39.6%
CVE-2019-10068KEV
High

Kentico contains a failure to validate security headers. This deserialization can led to unauthenticated remote code execution.

KenticoEPSS 93.9%
CVE-2017-6334KEV
High

dnslookup.cgi on NETGEAR DGN2200 devices with firmware through 10.0.0.50 allows remote authenticated users to execute arbitrary OS commands

NETGEAREPSS 89.2%
CVE-2019-12991KEV
High

Authenticated Command Injection in Citrix SD-WAN Appliance and NetScaler SD-WAN Appliance.

CitrixEPSS 81.0%
CVE-2018-11138KEV
High

The '/common/download_agent_installer.php' script in the Quest KACE System Management Appliance is accessible by anonymous users and can be abused to perform remote code execution.

QuestEPSS 93.4%
CVE-2019-1003030KEV
High

Jenkins Matrix Project plugin contains a vulnerability which can allow users to escape the sandbox, opening opportunity to perform remote code execution.

JenkinsEPSS 93.1%
CVE-2018-8373KEV
High

A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer.

MicrosoftEPSS 82.4%
CVE-2018-14839KEV
High

LG N1A1 NAS 3718.510 is affected by a remote code execution vulnerability.

LGEPSS 90.3%
CVE-2018-1273KEV
High

Spring Data Commons contains a property binder vulnerability which can allow an attacker to perform remote code execution.

VMware TanzuEPSS 94.3%
CVE-2021-22941KEV
High

Improper Access Control in Citrix ShareFile storage zones controller may allow an unauthenticated attacker to remotely compromise the storage zones controller.

CitrixEPSS 87.8%
CVE-2020-7247KEV
High

smtp_mailaddr in smtp_session.c in OpenSMTPD, as used in OpenBSD and other products, allows remote attackers to execute arbitrary commands as root via a crafted SMTP session.

OpenBSDEPSS 94.1%
CVE-2018-6961KEV
High

VMware SD-WAN Edge by VeloCloud contains a command injection vulnerability in the local web UI component. Successful exploitation of this issue could result in remote code execution.

VMwareEPSS 93.6%
CVE-2019-12989KEV
High

Citrix SD-WAN and NetScaler SD-WAN allow SQL Injection.

CitrixEPSS 91.1%
CVE-2018-0147KEV
High

A vulnerability in Java deserialization used by Cisco Secure Access Control System (ACS) could allow an unauthenticated, remote attacker to execute arbitrary commands on an affected device. The vulnerability is due to insecure deserialization of user-supplied content by the affected software.

CiscoEPSS 4.0%
CVE-2020-5410KEV
High

Spring, by VMware Tanzu, Cloud Config contains a path traversal vulnerability that allows applications to serve arbitrary configuration files.

VMware TanzuEPSS 94.3%
CVE-2020-9377KEV
High

D-Link DIR-610 devices allow remote code execution via the cmd parameter to command.php.

D-LinkEPSS 76.6%
CVE-2022-21999KEV
High

Microsoft Windows Print Spooler contains an unspecified vulnerability which can allow for privilege escalation.

MicrosoftEPSS 72.7%
CVE-2020-1631KEV
High

A path traversal vulnerability in the HTTP/HTTPS service used by J-Web, Web Authentication, Dynamic-VPN (DVPN), Firewall Authentication Pass-Through with Web-Redirect, and Zero Touch Provisioning (ZTP) allows an unauthenticated attacker to perform remote code execution.

JuniperEPSS 5.4%
CVE-2010-4344KEV
High

Heap-based buffer overflow in the string_vformat function in string.c in Exim before 4.70 allows remote attackers to execute arbitrary code via an SMTP session.

EximEPSS 61.5%
CVE-2019-6340KEV
High

In Drupal Core, some field types do not properly sanitize data from non-form sources. This can lead to arbitrary PHP code execution in some cases.

DrupalCVSS 8.1EPSS 94.4%
Exploit