Fixed Intel

CVE Tracker

Track known exploited vulnerabilities, CISA KEV alerts, and linked threat intelligence.

2,235

Total CVEs

1,590

CISA KEV

41

Known Exploits

8.8

Avg CVSS Score

Severity Distribution

CRITICAL 8
HIGH 1600
MEDIUM 7
INFO 620

Showing 20 of 2,235 CVEs

CVE-2015-1427KEV
High

The Groovy scripting engine in Elasticsearch allows remote attackers to bypass the sandbox protection mechanism and execute arbitrary shell commands.

ElasticEPSS 92.3%
CVE-2020-2506KEV
High

QNAP Helpdesk contains an improper access control vulnerability which could allow an attacker to gain privileges or to read sensitive information.

QNAP SystemsEPSS 18.0%
CVE-2019-11043KEV
High

In some versions of PHP in certain configurations of FPM setup, it is possible to cause FPM module to write past allocated buffers allowing the possibility of remote code execution.

PHPEPSS 94.1%
CVE-2022-26143KEV
High

A vulnerability has been identified in MiCollab and MiVoice Business Express that may allow a malicious actor to gain unauthorized access to sensitive information and services, cause performance degradations or a denial of service condition on the affected system.

MitelEPSS 89.2%
CVE-2015-4068KEV
High

Directory traversal vulnerability in Arcserve UDP allows remote attackers to obtain sensitive information or cause a denial of service.

ArcserveEPSS 80.9%
CVE-2019-15107KEV
High

An issue was discovered in Webmin. The parameter old in password_change.cgi contains a command injection vulnerability.

WebminEPSS 94.5%
CVE-2009-2055KEV
High

Cisco IOS XR,when BGP is the configured routing feature, allows remote attackers to cause a denial-of-service (DoS).

CiscoEPSS 0.4%
CVE-2016-0752KEV
High

Directory traversal vulnerability in Action View in Ruby on Rails allows remote attackers to read arbitrary files.

RailsEPSS 92.7%
CVE-2021-42237KEV
High

Sitcore XP contains an insecure deserialization vulnerability which can allow for remote code execution.

SitecoreEPSS 94.4%
CVE-2009-0927KEV
High

Stack-based buffer overflow in Adobe Reader and Adobe Acrobat allows remote attackers to execute arbitrary code.

AdobeEPSS 93.3%
CVE-2005-2773KEV
High

HP OpenView Network Node Manager could allow a remote attacker to execute arbitrary commands on the system.

Hewlett Packard (HP)EPSS 91.2%
CVE-2019-1132KEV
High

A privilege escalation vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory.

MicrosoftEPSS 35.6%
CVE-2019-1064KEV
High

A privilege escalation vulnerability exists when Windows AppXSVC improperly handles hard links. An attacker who successfully exploited this vulnerability could run processes in an elevated context.

MicrosoftEPSS 11.3%
CVE-2019-1129KEV
High

A privilege escalation vulnerability exists when Windows AppXSVC improperly handles hard links. An attacker who successfully exploited this vulnerability could run processes in an elevated context.

MicrosoftEPSS 3.1%
CVE-2019-1322KEV
High

A privilege escalation vulnerability exists when Windows improperly handles authentication requests. An attacker who successfully exploited this vulnerability could run processes in an elevated context.

MicrosoftEPSS 36.5%
CVE-2015-2546KEV
High

The kernel-mode driver in Microsoft Windows OS and Server allows local users to gain privileges via a crafted application.

MicrosoftEPSS 39.9%
CVE-2019-0543KEV
High

A privilege escalation vulnerability exists when Windows improperly handles authentication requests. An attacker who successfully exploited this vulnerability could run processes in an elevated context.

MicrosoftEPSS 16.6%
CVE-2017-0101KEV
High

A privilege escalation vulnerability exists when the Windows Transaction Manager improperly handles objects in memory.

MicrosoftEPSS 64.4%
CVE-2019-0841KEV
High

A privilege escalation vulnerability exists when Windows AppXSVC improperly handles hard links. An attacker who successfully exploited this vulnerability could run processes in an elevated context.

MicrosoftEPSS 82.7%
CVE-2016-3309KEV
High

A privilege escalation vulnerability exists when the Windows kernel fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode.

MicrosoftEPSS 43.0%