Rosetta Intel
Datasets/KEV CatalogThreat Actors
Rosetta Lab ↗Blur Horizon LLC
Datasets

KEV Catalog

CISA, queryable

Known exploited vulnerabilities as a queryable table — by CVE, vendor or product.

1676 entries·352 Ransomware·Updated 2026-08-25

CWE-158Definition on MITRE ↗Clear

3 results

CVE-2025-47812
2025-07-14
Wing FTP Server Improper Neutralization of Null Byte or NUL Character Vulnerability
Wing FTP Server

Wing FTP Server contains an improper neutralization of null byte or NUL character vulnerability that can allow injection of arbitrary Lua code into user session files. This can be used to execute arbitrary system commands with the privileges of the FTP service (root or SYSTEM by default).

CWE-158
Refswftpserver.comnvd.nist.gov
Federal remediation due 2025-08-04
CVE-2022-36804
2022-09-30
Atlassian Bitbucket Server and Data Center Command Injection Vulnerability
Atlassian

Multiple API endpoints of Atlassian Bitbucket Server and Data Center contain a command injection vulnerability where an attacker with access to a public Bitbucket repository, or with read permissions to a private one, can execute code by sending a malicious HTTP request.

CWE-78 · OS command injectionCWE-88CWE-158
Refsjira.atlassian.comnvd.nist.gov
Federal remediation due 2022-10-21
CVE-2022-1040
2022-03-31
Sophos Firewall Authentication Bypass Vulnerability
Sophos

An authentication bypass vulnerability in User Portal and Webadmin of Sophos Firewall allows for remote code execution.

CWE-158
Refsnvd.nist.gov
Federal remediation due 2022-04-21