Rosetta Intel
Datasets/KEV CatalogThreat Actors
Rosetta Lab ↗Blur Horizon LLC
Datasets

KEV Catalog

CISA, queryable

Known exploited vulnerabilities as a queryable table — by CVE, vendor or product.

1676 entries·352 Ransomware·Updated 2026-08-25

CWE-506Definition on MITRE ↗Clear

8 results

CVE-2026-8398
2026-05-27
Daemon Tools Lite Embedded Malicious Code Vulnerability
Daemon

Daemon Tools contains an unspecified vulnerability that has a high impact on confidentiality, integrity, and availability.

CWE-506
Refsblog.daemon-tools.ccnvd.nist.gov
Federal remediation due 2026-05-30
CVE-2026-48027
2026-05-27
Nx Console Embedded Malicious Code VulnerabilityRansomware
Nx

Nx Console contains an embedded malicious code vulnerability that allowed a malicious version of Nx Console to be published. The compromised extension fetched an obfuscated payload that could harvested credentials from multiple sources on disk and in memory.

CWE-506
RefsThis vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please seenvd.nist.gov
Federal remediation due 2026-06-10
CVE-2026-33634
2026-03-26
Aquasecurity Trivy Embedded Malicious Code Vulnerability
Aquasecurity

Aquasecurity Trivy contains an embedded malicious code vulnerability that could allow an attacker to gain access to everything in the CI/CD environment, including all tokens, SSH keys, cloud credentials, database passwords, and any sensitive configuration in memory.

CWE-506
RefsThis vulnerability involves a supply‑chain compromise in a product that may be used across multiple products and environments. Additional vendor‑provided guidance must be followed to ensure full remediation. For more information, please seenvd.nist.gov
Federal remediation due 2026-04-09
CVE-2025-54313
2026-01-22
Prettier eslint-config-prettier Embedded Malicious Code Vulnerability
Prettier

Prettier eslint-config-prettier contains an embedded malicious code vulnerability. Installing an affected package executes an install.js file that launches the node-gyp.dll malware on Windows.

CWE-506
RefsThis vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please seegithub.comnvd.nist.gov
Federal remediation due 2026-02-12
CVE-2025-59374
2025-12-17
ASUS Live Update Embedded Malicious Code Vulnerability
ASUS

ASUS Live Update contains an embedded malicious code vulnerability client were distributed with unauthorized modifications introduced through a supply chain compromise. The modified builds could cause devices meeting specific targeting conditions to perform unintended actions. The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.

CWE-506
Refsasus.comnvd.nist.gov
Federal remediation due 2026-01-07
CVE-2025-30154
2025-03-24
reviewdog/action-setup GitHub Action Embedded Malicious Code Vulnerability
reviewdog

reviewdog action-setup GitHub Action contains an embedded malicious code vulnerability that dumps exposed secrets to Github Actions Workflow Logs.

CWE-506
RefsThis vulnerability affects a common open-source project, third-party library, or a protocol used by different products. For more information, please see: CISA Mitigation InstructionsAdditional Referencesnvd.nist.gov
Federal remediation due 2025-04-14
CVE-2025-30066
2025-03-18
tj-actions/changed-files GitHub Action Embedded Malicious Code Vulnerability
tj-actions

tj-actions/changed-files GitHub Action contains an embedded malicious code vulnerability that allows a remote attacker to discover secrets by reading Github Actions Workflow Logs. These secrets may include, but are not limited to, valid AWS access keys, GitHub personal access tokens (PATs), npm tokens, and private RSA keys.

CWE-506
RefsThis vulnerability affects a common open-source project, third-party library, or a protocol used by different products. For more information, please see: CISA Mitigation InstructionsAdditional Referencesnvd.nist.gov
Federal remediation due 2025-04-08
CVE-2024-4978
2024-05-29
Justice AV Solutions (JAVS) Viewer Installer Embedded Malicious Code Vulnerability
Justice AV Solutions

Justice AV Solutions (JAVS) Viewer installer contains a malicious version of ffmpeg.exe, named fffmpeg.exe (SHA256: 421a4ad2615941b177b6ec4ab5e239c14e62af2ab07c6df1741e2a62223223c4). When run, this creates a backdoor connection to a malicious C2 server.

CWE-506
RefsPlease follow the vendor’s instructions as outlined in the public statements atnvd.nist.gov
Federal remediation due 2024-06-19