Rosetta Intel
Datasets/KEV CatalogThreat Actors
Rosetta Lab ↗Blur Horizon LLC
Datasets

KEV Catalog

CISA, queryable

Known exploited vulnerabilities as a queryable table — by CVE, vendor or product.

1676 entries·352 Ransomware·Updated 2026-08-25

CWE-347Definition on MITRE ↗Clear

5 results

CVE-2026-48558
2026-06-29
SimpleHelp Authentication Bypass Vulnerability
SimpleHelp

SimpleHelp contains an authentication bypass vulnerability in the OIDC authentication flow. When OIDC authentication is configured, identity tokens submitted during login are accepted without verifying their cryptographic signature. In a vulnerable configuration, a remote, unauthenticated attacker can submit a forged token containing arbitrary identity claims to obtain a fully authenticated technician session. In some configurations, this may also allow bypass of multi-factor authentication.

CWE-347
Refssimple-help.comBOD 26-04Forensics Triage Requirementsnvd.nist.gov
Federal remediation due 2026-07-02
CVE-2025-59718
2025-12-16
Fortinet Multiple Products Improper Verification of Cryptographic Signature Vulnerability
Fortinet

Fortinet FortiOS, FortiSwitchMaster, FortiProxy, and FortiWeb contain an improper verification of cryptographic signature vulnerability that may allow an unauthenticated attacker to bypass the FortiCloud SSO login authentication via a crafted SAML message. Please be aware that CVE-2025-59719 pertains to the same problem and is mentioned in the same vendor advisory. Ensure to apply all patches mentioned in the advisory.

CWE-347
Refsfortiguard.fortinet.comdocs.fortinet.comnvd.nist.gov
Federal remediation due 2025-12-23
CVE-2020-2021
2022-03-25
Palo Alto Networks PAN-OS Authentication Bypass VulnerabilityRansomware
Palo Alto Networks

Palo Alto Networks PAN-OS contains a vulnerability in SAML which allows an attacker to bypass authentication.

CWE-347
Refsnvd.nist.gov
Federal remediation due 2022-04-15
CVE-2022-20703
2022-03-03
Cisco Small Business RV Series Routers Stack-based Buffer Overflow Vulnerability
Cisco / Small Business RV160, RV260, RV340, and RV345 Series Routers

A vulnerability in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code elevate privileges, execute arbitrary commands, bypass authentication and authorization protections, fetch and run unsigned software, or cause a denial of service (DoS).

CWE-347
Refsnvd.nist.gov
Federal remediation due 2022-03-17
CVE-2020-1464
2021-11-03
Microsoft Windows Spoofing Vulnerability
Microsoft

Microsoft Windows contains a spoofing vulnerability when Windows incorrectly validates file signatures, allowing an attacker to bypass security features and load improperly signed files.

CWE-347
Refsnvd.nist.gov
Federal remediation due 2022-05-03