Rosetta Intel
Datasets/KEV CatalogThreat Actors
Rosetta Lab ↗Blur Horizon LLC
Datasets

KEV Catalog

CISA, queryable

Known exploited vulnerabilities as a queryable table — by CVE, vendor or product.

1676 entries·352 Ransomware·Updated 2026-08-25

CWE-420Definition on MITRE ↗Clear

2 results

CVE-2025-54309
2025-07-22
CrushFTP Unprotected Alternate Channel Vulnerability
CrushFTP

CrushFTP contains an unprotected alternate channel vulnerability. When the DMZ proxy feature is not used, mishandles AS2 validation and consequently allows remote attackers to obtain admin access via HTTPS.

CWE-420
Refscrushftp.comnvd.nist.gov
Federal remediation due 2025-08-12
CVE-2023-20198
2023-10-16
Cisco IOS XE Web UI Privilege Escalation Vulnerability
Cisco

Cisco IOS XE Web UI contains a privilege escalation vulnerability in the web user interface that could allow a remote, unauthenticated attacker to create an account with privilege level 15 access. The attacker can then use that account to gain control of the affected device.

CWE-420
Refscisco.comnvd.nist.gov
Federal remediation due 2023-10-20