Rosetta Intel
Datasets/KEV CatalogThreat Actors
Rosetta Lab ↗Blur Horizon LLC
Datasets

KEV Catalog

CISA, queryable

Known exploited vulnerabilities as a queryable table — by CVE, vendor or product.

1676 entries·352 Ransomware·Updated 2026-08-25

CWE-200 · Information exposureDefinition on MITRE ↗Clear

25 results

CVE-2025-68686
2026-07-27
Fortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability
Fortinet

Fortinet FortiOS contains an exposure of sensitive information to an unauthorized actor vulnerability. This may allow a remote unauthenticated attacker to bypass the patch developed for the symbolic link persistency mechanism observed in some post-exploit cases, via crafted HTTP requests. An attacker would need first to have compromised the product via another vulnerability, at filesystem level.

CWE-200 · Information exposure
Refsfortiguard.fortinet.comBOD 26-04Forensics Triage Requirementsnvd.nist.gov
Federal remediation due 2026-08-10
CVE-2026-20133
2026-04-20
Cisco Catalyst SD-WAN Manager Exposure of Sensitive Information to an Unauthorized Actor Vulnerability
Cisco

Cisco Catalyst SD-WAN Manager contains an exposure of sensitive information to an unauthorized actor vulnerability that could allow remote attackers to view sensitive information on affected systems.

CWE-200 · Information exposure
RefsCISA Mitigation Instructionscisa.govsec.cloudapps.cisco.comnvd.nist.gov
Federal remediation due 2026-04-23
CVE-2025-31125
2026-01-22
Vite Vitejs Improper Access Control Vulnerability
Vite

Vite Vitejs contains an improper access control vulnerability that exposes content of non-allowed files using ?inline&import or ?raw?import. Only apps explicitly exposing the Vite dev server to the network (using --host or server.host config option) are affected.

CWE-200 · Information exposureCWE-284 · Improper access control
RefsThis vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please seenvd.nist.gov
Federal remediation due 2026-02-12
CVE-2026-20805
2026-01-13
Microsoft Windows Information Disclosure Vulnerability
Microsoft

Microsoft Windows Desktop Windows Manager contains an information disclosure vulnerability that allows an authorized attacker to disclose information locally.

CWE-200 · Information exposure
Refsmsrc.microsoft.comnvd.nist.gov
Federal remediation due 2026-02-03
CVE-2021-41277
2024-11-12
Metabase GeoJSON API Local File Inclusion Vulnerability
Metabase

Metabase contains a local file inclusion vulnerability in the custom map support in the API to read GeoJSON formatted data.

CWE-200 · Information exposure
Refsgithub.comnvd.nist.gov
Federal remediation due 2024-12-03
CVE-2024-24919
2024-05-30
Check Point Quantum Security Gateways Information Disclosure VulnerabilityRansomware
Check Point

Check Point Quantum Security Gateways contain an unspecified information disclosure vulnerability. The vulnerability potentially allows an attacker to access information on Gateways connected to the internet, with IPSec VPN, Remote Access VPN or Mobile Access enabled. This issue affects several product lines from Check Point, including CloudGuard Network, Quantum Scalable Chassis, Quantum Security Gateways, and Quantum Spark Appliances.

CWE-200 · Information exposure
Refssupport.checkpoint.comnvd.nist.gov
Federal remediation due 2024-06-20
CVE-2023-21237
2024-03-05
Android Pixel Information Disclosure Vulnerability
Android

Android Pixel contains a vulnerability in the Framework component, where the UI may be misleading or insufficient, providing a means to hide a foreground service notification. This could enable a local attacker to disclose sensitive information.

CWE-200 · Information exposure
Refssource.android.comnvd.nist.gov
Federal remediation due 2024-03-26
CVE-2020-3259
2024-02-15
Cisco ASA and FTD Information Disclosure VulnerabilityRansomware
Cisco / Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD)

Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) contain an information disclosure vulnerability. An attacker could retrieve memory contents on an affected device, which could lead to the disclosure of confidential information due to a buffer tracking issue when the software parses invalid URLs that are requested from the web services interface. This vulnerability affects only specific AnyConnect and WebVPN configurations.

CWE-200 · Information exposure
Refstools.cisco.comnvd.nist.gov
Federal remediation due 2024-03-07
CVE-2016-6415
2023-05-19
Cisco IOS, IOS XR, and IOS XE IKEv1 Information Disclosure Vulnerability
Cisco

Cisco IOS, IOS XR, and IOS XE contain insufficient condition checks in the part of the code that handles Internet Key Exchange version 1 (IKEv1) security negotiation requests. contains an information disclosure vulnerability in the Internet Key Exchange version 1 (IKEv1) that could allow an attacker to retrieve memory contents. Successful exploitation could allow the attacker to retrieve memory contents, which can lead to information disclosure.

CWE-200 · Information exposure
Refssec.cloudapps.cisco.comnvd.nist.gov
Federal remediation due 2023-06-09
CVE-2015-5317
2023-05-12
Jenkins User Interface (UI) Information Disclosure Vulnerability
Jenkins

Jenkins User Interface (UI) contains an information disclosure vulnerability that allows users to see the names of jobs and builds otherwise inaccessible to them on the "Fingerprints" pages.

CWE-200 · Information exposure
Refsjenkins.ionvd.nist.gov
Federal remediation due 2023-06-02
CVE-2023-28432
2023-04-21
MinIO Information Disclosure Vulnerability
MinIO

MinIO contains a vulnerability in a cluster deployment where MinIO returns all environment variables, which allows for information disclosure.

CWE-200 · Information exposure
Refsgithub.comnvd.nist.gov
Federal remediation due 2023-05-12
CVE-2021-25369
2022-11-08
Samsung Mobile Devices Improper Access Control Vulnerability
Samsung

Samsung mobile devices using Mali GPU contains an improper access control vulnerability in sec_log file. Exploitation of the vulnerability exposes sensitive kernel information to the userspace. This vulnerability was chained with CVE-2021-25337 and CVE-2021-25370.

CWE-200 · Information exposure
Refssecurity.samsungmobile.comnvd.nist.gov
Federal remediation due 2022-11-29
CVE-2017-5521
2022-09-08
NETGEAR Multiple Devices Exposure of Sensitive Information Vulnerability
NETGEAR

Multiple NETGEAR devices are prone to admin password disclosure via simple crafted requests to the web management server.

CWE-200 · Information exposure
Refskb.netgear.comnvd.nist.gov
Federal remediation due 2022-09-29
CVE-2016-2388
2022-06-09
SAP NetWeaver Information Disclosure Vulnerability
SAP

The Universal Worklist Configuration in SAP NetWeaver AS JAVA 7.4 allows remote attackers to obtain sensitive user information via a crafted HTTP request.

CWE-200 · Information exposure
Refsnvd.nist.gov
Federal remediation due 2022-06-30
CVE-2015-4495
2022-05-25
Mozilla Firefox Security Feature Bypass Vulnerability
Mozilla

Moxilla Firefox allows remote attackers to bypass the Same Origin Policy to read arbitrary files or gain privileges.

CWE-200 · Information exposure
Refsnvd.nist.gov
Federal remediation due 2022-06-15
CVE-2013-7331
2022-05-25
Microsoft Internet Explorer Information Disclosure Vulnerability
Microsoft

An information disclosure vulnerability exists in Internet Explorer which allows resources loaded into memory to be queried. This vulnerability could allow an attacker to detect anti-malware applications.

CWE-200 · Information exposure
Refsnvd.nist.gov
Federal remediation due 2022-06-15
CVE-2017-0147
2022-05-24
Microsoft Windows SMBv1 Information Disclosure VulnerabilityRansomware
Microsoft / SMBv1 server

The SMBv1 server in Microsoft Windows allows remote attackers to obtain sensitive information from process memory via a crafted packet.

CWE-200 · Information exposure
Refsnvd.nist.gov
Federal remediation due 2022-06-14
CVE-2017-0022
2022-05-24
Microsoft XML Core Services Information Disclosure Vulnerability
Microsoft

Microsoft XML Core Services (MSXML) improperly handles objects in memory, allowing attackers to test for files on disk via a crafted web site.

CWE-200 · Information exposure
Refsnvd.nist.gov
Federal remediation due 2022-06-14
CVE-2016-4655
2022-05-24
Apple iOS Information Disclosure Vulnerability
Apple

The Apple iOS kernel allows attackers to obtain sensitive information from memory via a crafted application.

CWE-200 · Information exposure
Refsnvd.nist.gov
Federal remediation due 2022-06-14
CVE-2016-3351
2022-05-24
Microsoft Internet Explorer and Edge Information Disclosure VulnerabilityRansomware
Microsoft

An information disclosure vulnerability exists in the way that certain functions in Internet Explorer and Edge handle objects in memory. The vulnerability could allow an attacker to detect specific files on the user's computer.

CWE-200 · Information exposure
Refsnvd.nist.gov
Federal remediation due 2022-06-14
CVE-2016-3298
2022-05-24
Microsoft Internet Explorer Messaging API Information Disclosure Vulnerability
Microsoft

An information disclosure vulnerability exists when the Microsoft Internet Messaging API improperly handles objects in memory. An attacker who successfully exploited this vulnerability could allow the attacker to test for the presence of files on disk.

CWE-200 · Information exposure
Refsnvd.nist.gov
Federal remediation due 2022-06-14
CVE-2016-0162
2022-05-24
Microsoft Internet Explorer Information Disclosure Vulnerability
Microsoft

An information disclosure vulnerability exists when Internet Explorer does not properly handle JavaScript. The vulnerability could allow an attacker to detect specific files on the user's computer.

CWE-200 · Information exposure
Refsnvd.nist.gov
Federal remediation due 2022-06-14
CVE-2017-0059
2022-03-28
Microsoft Internet Explorer Information Disclosure Vulnerability
Microsoft

Microsoft Internet Explorer allow remote attackers to obtain sensitive information from process memory via a crafted web site.

CWE-200 · Information exposure
Refsnvd.nist.gov
Federal remediation due 2022-04-18
CVE-2013-0631
2022-03-07
Adobe ColdFusion Information Disclosure Vulnerability
Adobe

Adobe Coldfusion contains an unspecified vulnerability, which could result in information disclosure from a compromised server.

CWE-200 · Information exposure
Refsnvd.nist.gov
Federal remediation due 2022-09-07
CVE-2013-0632
2022-03-03
Adobe ColdFusion Authentication Bypass Vulnerability
Adobe

An authentication bypass vulnerability exists in Adobe ColdFusion which could result in an unauthorized user gaining administrative access.

CWE-200 · Information exposure
Refsnvd.nist.gov
Federal remediation due 2022-03-24