Rosetta Intel
Datasets/KEV CatalogThreat Actors
Rosetta Lab ↗Blur Horizon LLC
Datasets

KEV Catalog

CISA, queryable

Known exploited vulnerabilities as a queryable table — by CVE, vendor or product.

1676 entries·352 Ransomware·Updated 2026-08-25

CWE-367Definition on MITRE ↗Clear

5 results

CVE-2025-38352
2025-09-04
Linux Kernel Time-of-Check Time-of-Use (TOCTOU) Race Condition Vulnerability
Linux

Linux kernel contains a time-of-check time-of-use (TOCTOU) race condition vulnerability that has a high impact on confidentiality, integrity, and availability.

CWE-367
RefsThis vulnerability affects a common open-source component, third-party library, or a protocol used by different products. Please check with specific vendors for information on patching status. For more information, please seesource.android.comnvd.nist.gov
Federal remediation due 2025-09-25
CVE-2025-22224
2025-03-04
VMware ESXi and Workstation TOCTOU Race Condition Vulnerability
VMware

VMware ESXi and Workstation contain a time-of-check time-of-use (TOCTOU) race condition vulnerability that leads to an out-of-bounds write. Successful exploitation enables an attacker with local administrative privileges on a virtual machine to execute code as the virtual machine's VMX process running on the host.

CWE-367
Refssupport.broadcom.comnvd.nist.gov
Federal remediation due 2025-03-25
CVE-2024-30088
2024-10-15
Microsoft Windows Kernel TOCTOU Race Condition VulnerabilityRansomware
Microsoft

Microsoft Windows Kernel contains a time-of-check to time-of-use (TOCTOU) race condition vulnerability that could allow for privilege escalation.

CWE-367
Refsmsrc.microsoft.comnvd.nist.gov
Federal remediation due 2024-11-05
CVE-2022-48618
2024-01-31
Apple Multiple Products Memory Corruption Vulnerability
Apple

Apple iOS, iPadOS, macOS, tvOS, and watchOS contain a time-of-check/time-of-use (TOCTOU) memory corruption vulnerability that allows an attacker with read and write capabilities to bypass Pointer Authentication.

CWE-367
Refssupport.apple.comnvd.nist.gov
Federal remediation due 2024-02-21
CVE-2023-35311
2023-07-11
Microsoft Outlook Security Feature Bypass Vulnerability
Microsoft

Microsoft Outlook contains a security feature bypass vulnerability that allows an attacker to bypass the Microsoft Outlook Security Notice prompt.

CWE-367
Refsmsrc.microsoft.comnvd.nist.gov
Federal remediation due 2023-08-01