Rosetta Intel
Datasets/KEV CatalogThreat ActorsAttack Surface
Rosetta Lab ↗Blur Horizon LLC
Datasets

KEV Catalog

CISA, queryable

Known exploited vulnerabilities as a queryable table — by CVE, vendor or product.

1685 entries·352 Ransomware·Updated 2026-08-27

CWE-295Definition on MITRE ↗Clear

4 results

CVE-2023-41991
2023-09-25
Apple Multiple Products Improper Certificate Validation Vulnerability
Apple

Apple iOS, iPadOS, macOS, and watchOS contain an improper certificate validation vulnerability that can allow a malicious app to bypass signature validation.

CWE-295
Refssupport.apple.comnvd.nist.gov
Federal remediation due 2023-10-16
CVE-2023-20963
2023-04-13
Android Framework Privilege Escalation Vulnerability
Android

Android Framework contains an unspecified vulnerability that allows for privilege escalation after updating an app to a higher Target SDK with no additional execution privileges needed.

CWE-295
Refssource.android.comnvd.nist.gov
Federal remediation due 2023-05-04
CVE-2022-26923
2022-08-18
Microsoft Active Directory Domain Services Privilege Escalation Vulnerability
Microsoft

An authenticated user could manipulate attributes on computer accounts they own or manage, and acquire a certificate from Active Directory Certificate Services that would allow for privilege escalation to SYSTEM.

CWE-295
Refsmsrc.microsoft.comnvd.nist.gov
Federal remediation due 2022-09-08
CVE-2020-0601
2021-11-03
Microsoft Windows CryptoAPI Spoofing Vulnerability
Microsoft

Microsoft Windows CryptoAPI (Crypt32.dll) contains a spoofing vulnerability in the way it validates Elliptic Curve Cryptography (ECC) certificates. An attacker could exploit the vulnerability by using a spoofed code-signing certificate to sign a malicious executable, making it appear the file was from a trusted, legitimate source. A successful exploit could also allow the attacker to conduct man-in-the-middle attacks and decrypt confidential information on user connections to the affected software. The vulnerability is also known under the moniker of CurveBall.

CWE-295
RefsReference CISA's ED 20-02 (
Federal remediation due 2022-05-03