Fixed Intel

CVE Tracker

Track known exploited vulnerabilities, CISA KEV alerts, and linked threat intelligence.

2,235

Total CVEs

1,590

CISA KEV

41

Known Exploits

8.8

Avg CVSS Score

Severity Distribution

CRITICAL 8
HIGH 1600
MEDIUM 7
INFO 620

Showing 20 of 2,235 CVEs

CVE-2017-12319KEV
High

A vulnerability in the Border Gateway Protocol (BGP) over an Ethernet Virtual Private Network (EVPN) for Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause the device to reload, resulting in a denial of service (DoS) condition, or potentially corrupt the BGP routing table, which could result in network instability.

CiscoEPSS 1.3%
CVE-2022-20700KEV
High

A vulnerability in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code elevate privileges, execute arbitrary commands, bypass authentication and authorization protections, fetch and run unsigned software, or cause a denial of service (DoS).

CiscoEPSS 21.8%
CVE-2022-20701KEV
High

A vulnerability in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code elevate privileges, execute arbitrary commands, bypass authentication and authorization protections, fetch and run unsigned software, or cause a denial of service (DoS).

CiscoEPSS 6.1%
CVE-2019-1652KEV
High

A vulnerability in the web-based management interface of Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers could allow an authenticated, remote attacker with administrative privileges on an affected device to execute arbitrary commands.

CiscoEPSS 93.0%
CVE-2022-20699KEV
High

A vulnerability in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code elevate privileges, execute arbitrary commands, bypass authentication and authorization protections, fetch and run unsigned software, or cause a denial of service (DoS).

CiscoEPSS 89.9%
CVE-2020-11899KEV
High

The Treck TCP/IP stack contains an IPv6 out-of-bounds read vulnerability.

Treck TCP/IP stackEPSS 33.3%
CVE-2021-41379KEV
High

Microsoft Windows Installer contains an unspecified vulnerability that allows for privilege escalation.

MicrosoftEPSS 1.2%
CVE-2020-1938KEV
High

Apache Tomcat treats Apache JServ Protocol (AJP) connections as having higher trust than, for example, a similar HTTP connection. If such connections are available to an attacker, they can be exploited.

ApacheCVSS 9.8EPSS 94.5%
Exploit
CVE-2022-20708KEV
High

A vulnerability in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code elevate privileges, execute arbitrary commands, bypass authentication and authorization protections, fetch and run unsigned software, or cause a denial of service (DoS).

CiscoEPSS 13.0%
CVE-2015-1642KEV
High

Microsoft Office contains a memory corruption vulnerability that allows remote attackers to execute arbitrary code via a crafted document.

MicrosoftEPSS 72.9%
CVE-2016-0099KEV
High

A privilege escalation vulnerability exists in Microsoft Windows if the Windows Secondary Logon Service fails to properly manage request handles in memory. An attacker who successfully exploited this vulnerability could run arbitrary code as an administrator.

MicrosoftEPSS 90.4%
CVE-2011-1889KEV
High

A remote code execution vulnerability exists in the Forefront Threat Management Gateway (TMG) Firewall Client Winsock provider that could allow code execution in the security context of the client application.

MicrosoftEPSS 85.4%
CVE-2022-24682KEV
High

Synacor Zimbra Collaboration Suite (ZCS) contains a cross-site scripting (XSS) vulnerability in the Calendar feature that allows an attacker to execute arbitrary code.

SynacorEPSS 88.0%
CVE-2017-0222KEV
High

A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory.

MicrosoftEPSS 62.0%
CVE-2017-8570KEV
High

A remote code execution vulnerability exists in Microsoft Office software when it fails to properly handle objects in memory.

MicrosoftEPSS 94.2%
CVE-2014-6352KEV
High

Microsoft Windows allow remote attackers to execute arbitrary code via a crafted OLE object.

MicrosoftEPSS 90.7%
CVE-2022-23134KEV
High

Malicious actors can pass step checks and potentially change the configuration of Zabbix Frontend.

ZabbixEPSS 93.1%
CVE-2022-23131KEV
High

Unsafe client-side session storage leading to authentication bypass/instance takeover via Zabbix Frontend with configured SAML.

ZabbixEPSS 94.3%
CVE-2019-0752KEV
High

A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer

MicrosoftEPSS 92.0%
CVE-2018-20250KEV
High

WinRAR Absolute Path Traversal vulnerability leads to Remote Code Execution

RARLABEPSS 93.5%