Rosetta Intel
Datasets/KEV CatalogThreat Actors
Rosetta Lab ↗Blur Horizon LLC
Datasets

KEV Catalog

CISA, queryable

Known exploited vulnerabilities as a queryable table — by CVE, vendor or product.

1676 entries·352 Ransomware·Updated 2026-08-25

CWE-1188Definition on MITRE ↗Clear

5 results

CVE-2025-48927
2025-07-01
TeleMessage TM SGNL Initialization of a Resource with an Insecure Default Vulnerability
TeleMessage

TeleMessage TM SGNL contains an initialization of a resource with an insecure default vulnerability. This vulnerability relies on how the Spring Boot Actuator is configured with an exposed heap dump endpoint at a /heapdump URI.

CWE-1188
Refsnvd.nist.gov
Federal remediation due 2025-07-22
CVE-2023-27524
2024-01-08
Apache Superset Insecure Default Initialization of Resource Vulnerability
Apache

Apache Superset contains an insecure default initialization of a resource vulnerability that allows an attacker to authenticate and access unauthorized resources on installations that have not altered the default configured SECRET_KEY according to installation instructions.

CWE-1188
Refslists.apache.orgnvd.nist.gov
Federal remediation due 2024-01-29
CVE-2023-6448
2023-12-11
Unitronics Vision PLC and HMI Insecure Default Password Vulnerability
Unitronics

Unitronics Vision Series PLCs and HMIs ship with an insecure default password, which if left unchanged, can allow attackers to execute remote commands.

CWE-1188
RefsNote that while it is possible to change the default password, implementors are encouraged to remove affected controllers from public networks and update the affected firmwarenvd.nist.gov
Federal remediation due 2023-12-18
CVE-2022-24706
2022-08-25
Apache CouchDB Insecure Default Initialization of Resource Vulnerability
Apache

Apache CouchDB contains an insecure default initialization of resource vulnerability which can allow an attacker to escalate to administrative privileges.

CWE-1188
Refslists.apache.orgnvd.nist.gov
Federal remediation due 2022-09-15
CVE-2020-13927
2022-01-18
Apache Airflow's Experimental API Authentication Bypass
Apache

The previous default setting for Airflow's Experimental API was to allow all API requests without authentication.

CWE-1188CWE-306 · Missing authentication
Refsnvd.nist.gov
Federal remediation due 2022-07-18