Fixed Intel

CVE Tracker

Track known exploited vulnerabilities, CISA KEV alerts, and linked threat intelligence.

2,235

Total CVEs

1,590

CISA KEV

41

Known Exploits

8.8

Avg CVSS Score

Severity Distribution

CRITICAL 8
HIGH 1600
MEDIUM 7
INFO 620

Showing 20 of 2,235 CVEs

CVE-2012-1856KEV
High

The TabStrip ActiveX control in the Common Controls in MSCOMCTL.OCX in Microsoft Office allows remote attackers to execute arbitrary code via a crafted (1) document or (2) web page that triggers system-state corruption.

MicrosoftEPSS 91.9%
CVE-2011-0611KEV
High

Adobe Flash Player contains a vulnerability that allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via crafted Flash content.

AdobeEPSS 93.6%
CVE-2011-3544KEV
High

An access control vulnerability exists in the Applet Rhino Script Engine component of Oracle's Java Runtime Environment allows an attacker to remotely execute arbitrary code.

OracleEPSS 92.6%
CVE-2017-12231KEV
High

A vulnerability in the implementation of Network Address Translation (NAT) functionality in Cisco IOS could allow an unauthenticated, remote attacker to cause a denial of service.

CiscoEPSS 6.8%
CVE-2018-8298KEV
High

The ChakraCore scripting engine contains a type confusion vulnerability which can allow for remote code execution.

ChakraCoreEPSS 90.3%
CVE-2017-12233KEV
High

There is a vulnerability in the implementation of the Common Industrial Protocol (CIP) feature in Cisco IOS could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial of service.

CiscoEPSS 6.5%
CVE-2013-3346KEV
High

Adobe Reader and Acrobat contain a memory corruption vulnerability which can allow attackers to execute arbitrary code or cause a denial of service.

AdobeEPSS 89.9%
CVE-2019-16928KEV
High

Exim contains an out-of-bounds write vulnerability which can allow for remote code execution.

EximEPSS 89.8%
CVE-2017-11292KEV
High

Adobe Flash Player contains a type confusion vulnerability which can allow for remote code execution.

AdobeEPSS 21.2%
CVE-2017-12235KEV
High

A vulnerability in the implementation of the PROFINET Discovery and Configuration Protocol (PN-DCP) for Cisco IOS could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial of service.

CiscoEPSS 4.9%
CVE-2015-2424KEV
High

Microsoft PowerPoint allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted Office document.

MicrosoftEPSS 84.3%
CVE-2010-0188KEV
High

Unspecified vulnerability in Adobe Reader and Acrobat allows attackers to cause a denial of service or possibly execute arbitrary code.

AdobeEPSS 93.4%
CVE-2012-1535KEV
High

Unspecified vulnerability in Adobe Flash Player allows remote attackers to execute arbitrary code or cause a denial of service via crafted SWF content.

AdobeEPSS 91.4%
CVE-2010-0232KEV
High

The kernel in Microsoft Windows, when access to 16-bit applications is enabled on a 32-bit x86 platform, does not properly validate certain BIOS calls, which allows local users to gain privileges.

MicrosoftEPSS 72.6%
CVE-2008-2992KEV
High

Adobe Acrobat and Reader contain an input validation issue in a JavaScript method that could potentially lead to remote code execution.

AdobeEPSS 93.7%
CVE-2004-0210KEV
High

A privilege elevation vulnerability exists in the POSIX subsystem. This vulnerability could allow a logged on user to take complete control of the system.

MicrosoftEPSS 3.7%
CVE-2008-3431KEV
High

An input validation vulnerability exists in the VBoxDrv.sys driver of Sun xVM VirtualBox which allows attackers to locally execute arbitrary code.

OracleEPSS 5.4%
CVE-2015-3043KEV
High

A memory corruption vulnerability exists in Adobe Flash Player that allows an attacker to perform remote code execution.

AdobeEPSS 83.9%
CVE-2002-0367KEV
High

smss.exe debugging subsystem in Microsoft Windows does not properly authenticate programs that connect to other programs, which allows local users to gain administrator or SYSTEM privileges.

MicrosoftEPSS 1.2%
CVE-2014-4114KEV
High

A vulnerability exists in Windows Object Linking & Embedding (OLE) that could allow remote code execution if a user opens a file that contains a specially crafted OLE object.

MicrosoftEPSS 92.1%