Rosetta Intel
Datasets/KEV CatalogThreat Actors
Rosetta Lab ↗Blur Horizon LLC
Datasets

KEV Catalog

CISA, queryable

Known exploited vulnerabilities as a queryable table — by CVE, vendor or product.

1676 entries·352 Ransomware·Updated 2026-08-25

CWE-250Definition on MITRE ↗Clear

3 results

CVE-2025-40602
2025-12-17
SonicWall SMA1000 Missing Authorization Vulnerability
SonicWall / SMA1000 appliance

SonicWall SMA1000 contains a missing authorization vulnerability that could allow for privilege escalation appliance management console (AMC) of affected devices.

CWE-862 · Missing authorizationCWE-250
RefsCheck for signs of potential compromise on all internet accessible SonicWall SMA1000 instances after applying mitigations. For more information please seenvd.nist.gov
Federal remediation due 2025-12-24
CVE-2024-38813
2024-11-20
VMware vCenter Server Privilege Escalation Vulnerability
VMware

VMware vCenter contains an improper check for dropped privileges vulnerability. This vulnerability could allow an attacker with network access to the vCenter Server to escalate privileges to root by sending a specially crafted packet.

CWE-250CWE-273
Refssupport.broadcom.comnvd.nist.gov
Federal remediation due 2024-12-11
CVE-2022-22960
2022-04-15
VMware Multiple Products Privilege Escalation Vulnerability
VMware

VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a privilege escalation vulnerability due to improper permissions in support scripts.

CWE-250
Refsnvd.nist.gov
Federal remediation due 2022-05-06