Rosetta Intel
Datasets/KEV CatalogThreat Actors
Rosetta Lab ↗Blur Horizon LLC
Datasets

KEV Catalog

CISA, queryable

Known exploited vulnerabilities as a queryable table — by CVE, vendor or product.

1676 entries·352 Ransomware·Updated 2026-08-25

CWE-20 · Improper input validationDefinition on MITRE ↗Clear

118 results·Page 3 / 3

CVE-2020-8195
2021-11-03
Citrix ADC, Gateway, and SD-WAN WANOP Appliance Information Disclosure Vulnerability
Citrix / Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance

Citrix ADC, Citrix Gateway, and multiple Citrix SD-WAN WANOP appliance models contain an information disclosure vulnerability.

CWE-20 · Improper input validation
Refsnvd.nist.gov
Federal remediation due 2022-05-03
CVE-2020-3452
2021-11-03
Cisco ASA and FTD Read-Only Path Traversal Vulnerability
Cisco / Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD)

Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) contain an improper input validation vulnerability when HTTP requests process URLs. An attacker could exploit this vulnerability by sending a crafted HTTP request containing directory traversal character sequences to an affected device. A successful exploit could allow the attacker to view arbitrary files within the web services file system on the targeted device.

CWE-20 · Improper input validation
Refsnvd.nist.gov
Federal remediation due 2022-05-03
CVE-2020-3161
2021-11-03
Cisco IP Phones Web Server Remote Code Execution and Denial-of-Service Vulnerability
Cisco

Cisco IP Phones contain an improper input validation vulnerability for HTTP requests. Exploitation could allow an attacker to execute code remotely with root privileges or cause a denial-of-service (DoS) condition.

CWE-20 · Improper input validation
Refsnvd.nist.gov
Federal remediation due 2022-05-03
CVE-2020-1040
2021-11-03
Microsoft Hyper-V RemoteFX vGPU Remote Code Execution Vulnerability
Microsoft

Microsoft Hyper-V RemoteFX vGPU contains an improper input validation vulnerability due to the host server failing to properly validate input from an authenticated user on a guest operating system. Successful exploitation allows for remote code execution on the host operating system.

CWE-20 · Improper input validation
Refsnvd.nist.gov
Federal remediation due 2022-05-03
CVE-2020-0041
2021-11-03
Android Kernel Out-of-Bounds Write Vulnerability
Android

Android Kernel binder_transaction of binder.c contains an out-of-bounds write vulnerability due to an incorrect bounds check that could allow for local privilege escalation. This vulnerability was observed chained with CVE-2019-2215 and CVE-2020-0069 under exploit chain "AbstractEmu."

CWE-20 · Improper input validation
Refsnvd.nist.gov
Federal remediation due 2022-05-03
CVE-2019-0604
2021-11-03
Microsoft SharePoint Remote Code Execution VulnerabilityRansomware
Microsoft

Microsoft SharePoint fails to check the source markup of an application package. An attacker who successfully exploits the vulnerability could run remote code in the context of the SharePoint application pool and the SharePoint server farm account.

CWE-20 · Improper input validation
Refsnvd.nist.gov
Federal remediation due 2022-05-03
CVE-2018-7600
2021-11-03
Drupal Core Remote Code Execution VulnerabilityRansomware
Drupal

Drupal Core contains a remote code execution vulnerability that could allow an attacker to exploit multiple attack vectors on a Drupal site, resulting in complete site compromise.

CWE-20 · Improper input validation
Refsnvd.nist.gov
Federal remediation due 2022-05-03
CVE-2018-20062
2021-11-03
ThinkPHP "noneCms" Remote Code Execution Vulnerability
ThinkPHP

ThinkPHP "noneCms" contains an unspecified vulnerability that allows for remote code execution through crafted use of the filter parameter.

CWE-20 · Improper input validation
Refsnvd.nist.gov
Federal remediation due 2022-05-03
CVE-2018-11776
2021-11-03
Apache Struts Remote Code Execution Vulnerability
Apache

Apache Struts contains a vulnerability that allows for remote code execution under two circumstances. One, where the alwaysSelectFullNamespace option is true and the value isn't set for a result defined in underlying configurations and in same time, its upper package configuration have no or wildcard namespace. Or, using URL tag which doesn't have value and action set and in same time, its upper package configuration have no or wildcard namespace.

CWE-20 · Improper input validation
Refsnvd.nist.gov
Federal remediation due 2022-05-03
CVE-2018-0296
2021-11-03
Cisco Adaptive Security Appliance (ASA) Denial-of-Service Vulnerability
Cisco

Cisco Adaptive Security Appliance (ASA) contains an improper input validation vulnerability with HTTP URLs. Exploitation could allow an attacker to cause a denial-of-service (DoS) condition or information disclosure.

CWE-20 · Improper input validation
Refsnvd.nist.gov
Federal remediation due 2022-05-03
CVE-2018-0171
2021-11-03
Cisco IOS and IOS XE Software Smart Install Remote Code Execution Vulnerability
Cisco

Cisco IOS and IOS XE Software improperly validates packet data, allowing an unauthenticated, remote attacker to trigger a reload of an affected device, cause a denial-of-service (DoS) condition, or perform code execution on the affected device.

CWE-20 · Improper input validation
Refsnvd.nist.gov
Federal remediation due 2022-05-03
CVE-2017-9822
2021-11-03
DotNetNuke (DNN) Remote Code Execution VulnerabilityRansomware
DotNetNuke (DNN)

DotNetNuke (DNN) contains a vulnerability that may allow for remote code execution via cookie deserialization.

CWE-20 · Improper input validation
Refsnvd.nist.gov
Federal remediation due 2022-05-03
CVE-2017-8759
2021-11-03
Microsoft .NET Framework Remote Code Execution Vulnerability
Microsoft

Microsoft .NET Framework contains a remote code execution vulnerability when processing untrusted input that could allow an attacker to take control of an affected system.

CWE-20 · Improper input validation
Refsnvd.nist.gov
Federal remediation due 2022-05-03
CVE-2017-6327
2021-11-03
Symantec Messaging Gateway Remote Code Execution Vulnerability
Symantec

Symantec Messaging Gateway contains an unspecified vulnerability which can allow for remote code execution. With the ability to perform remote code execution, an attacker may also desire to perform privilege escalating actions.

CWE-20 · Improper input validation
Refsnvd.nist.gov
Federal remediation due 2022-05-03
CVE-2017-5638
2021-11-03
Apache Struts Remote Code Execution VulnerabilityRansomware
Apache

Apache Struts Jakarta Multipart parser allows for malicious file upload using the Content-Type value, leading to remote code execution.

CWE-20 · Improper input validation
Refsnvd.nist.gov
Federal remediation due 2022-05-03
CVE-2017-0143
2021-11-03
Microsoft Windows Server Message Block (SMBv1) Remote Code Execution VulnerabilityRansomware
Microsoft

Microsoft Windows Server Message Block 1.0 (SMBv1) contains an unspecified vulnerability that allows for remote code execution.

CWE-20 · Improper input validation
Refsnvd.nist.gov
Federal remediation due 2022-05-03
CVE-2016-3718
2021-11-03
ImageMagick Server-Side Request Forgery (SSRF) Vulnerability
ImageMagick

ImageMagick contains an unspecified vulnerability that allows attackers to perform server-side request forgery (SSRF) via a crafted image.

CWE-20 · Improper input validation
Refsnvd.nist.gov
Federal remediation due 2022-05-03
CVE-2016-0185
2021-11-03
Microsoft Windows Media Center Remote Code Execution Vulnerability
Microsoft

Microsoft Windows Media Center contains a remote code execution vulnerability when Windows Media Center opens a specially crafted Media Center link (.mcl) file that references malicious code.

CWE-20 · Improper input validation
Refsnvd.nist.gov
Federal remediation due 2022-05-03
Prev3 / 3Next