Rosetta Intel
Datasets/KEV CatalogThreat ActorsAttack Surface
Rosetta Lab ↗Blur Horizon LLC
Datasets

KEV Catalog

CISA, queryable

Known exploited vulnerabilities as a queryable table — by CVE, vendor or product.

1685 entries·352 Ransomware·Updated 2026-08-27

CWE-427Definition on MITRE ↗Clear

2 results

CVE-2020-3433
2022-10-24
Cisco AnyConnect Secure Mobility Client for Windows DLL Hijacking VulnerabilityRansomware
Cisco

Cisco AnyConnect Secure Mobility Client for Windows interprocess communication (IPC) channel allows for insufficient validation of resources that are loaded by the application at run time. An attacker with valid credentials on Windows could execute code on the affected machine with SYSTEM privileges.

CWE-427
Refstools.cisco.comnvd.nist.gov
Federal remediation due 2022-11-14
CVE-2020-3153
2022-10-24
Cisco AnyConnect Secure Mobility Client for Windows Uncontrolled Search Path VulnerabilityRansomware
Cisco

Cisco AnyConnect Secure Mobility Client for Windows allows for incorrect handling of directory paths. An attacker with valid credentials on Windows would be able to copy malicious files to arbitrary locations with system level privileges. This could include DLL pre-loading, DLL hijacking, and other related attacks.

CWE-427
Refstools.cisco.comnvd.nist.gov
Federal remediation due 2022-11-14