Rosetta Intel
Datasets/KEV CatalogThreat Actors
Rosetta Lab ↗Blur Horizon LLC
Datasets

KEV Catalog

CISA, queryable

Known exploited vulnerabilities as a queryable table — by CVE, vendor or product.

1676 entries·352 Ransomware·Updated 2026-08-25

CWE-305Definition on MITRE ↗Clear

2 results

CVE-2025-31161
2025-04-07
CrushFTP Authentication Bypass VulnerabilityRansomware
CrushFTP

CrushFTP contains an authentication bypass vulnerability in the HTTP authorization header that allows a remote unauthenticated attacker to authenticate to any known or guessable user account (e.g., crushadmin), potentially leading to a full compromise.

CWE-305
Refscrushftp.comnvd.nist.gov
Federal remediation due 2025-04-28
CVE-2024-37085
2024-07-30
VMware ESXi Authentication Bypass VulnerabilityRansomware
VMware

VMware ESXi contains an authentication bypass vulnerability. A malicious actor with sufficient Active Directory (AD) permissions can gain full access to an ESXi host that was previously configured to use AD for user management by re-creating the configured AD group ('ESXi Admins' by default) after it was deleted from AD.

CWE-305
Refssupport.broadcom.comnvd.nist.gov
Federal remediation due 2024-08-20