Rosetta Intel
Datasets/KEV CatalogThreat Actors
Rosetta Lab ↗Blur Horizon LLC
Datasets

KEV Catalog

CISA, queryable

Known exploited vulnerabilities as a queryable table — by CVE, vendor or product.

1676 entries·352 Ransomware·Updated 2026-08-25

CWE-290Definition on MITRE ↗Clear

5 results

CVE-2023-50224
2025-09-03
TP-Link TL-WR841N Authentication Bypass by Spoofing Vulnerability
TP-Link

TP-Link TL-WR841N contains an authentication bypass by spoofing vulnerability within the httpd service, which listens on TCP port 80 by default, leading to the disclose of stored credentials. The impacted products could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.

CWE-290
Refstp-link.comnvd.nist.gov
Federal remediation due 2025-09-24
CVE-2024-54085
2025-06-25
AMI MegaRAC SPx Authentication Bypass by Spoofing Vulnerability
AMI

AMI MegaRAC SPx contains an authentication bypass by spoofing vulnerability in the Redfish Host Interface. A successful exploitation of this vulnerability may lead to a loss of confidentiality, integrity, and/or availability.

CWE-290
RefsThis vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please seesecurity.netapp.comnvd.nist.gov
Federal remediation due 2025-07-16
CVE-2024-4358
2024-06-13
Progress Telerik Report Server Authentication Bypass by Spoofing Vulnerability
Progress

Progress Telerik Report Server contains an authorization bypass by spoofing vulnerability that allows an attacker to obtain unauthorized access.

CWE-290
Refsdocs.telerik.comnvd.nist.gov
Federal remediation due 2024-07-04
CVE-2022-24112
2022-08-25
Apache APISIX Authentication Bypass Vulnerability
Apache

Apache APISIX contains an authentication bypass vulnerability that allows for remote code execution.

CWE-290
Refslists.apache.orgnvd.nist.gov
Federal remediation due 2022-09-15
CVE-2022-23131
2022-02-22
Zabbix Frontend Authentication Bypass Vulnerability
Zabbix

Unsafe client-side session storage leading to authentication bypass/instance takeover via Zabbix Frontend with configured SAML.

CWE-290
Refsnvd.nist.gov
Federal remediation due 2022-03-08