Rosetta Intel
Datasets/KEV CatalogThreat Actors
Rosetta Lab ↗Blur Horizon LLC
Datasets

KEV Catalog

CISA, queryable

Known exploited vulnerabilities as a queryable table — by CVE, vendor or product.

1676 entries·352 Ransomware·Updated 2026-08-25

CWE-522Definition on MITRE ↗Clear

4 results

CVE-2021-22681
2026-03-05
Rockwell Multiple Products Insufficient Protected Credentials Vulnerability
Rockwell

Multiple Rockwell products contain an insufficient protected credentials vulnerability. Studio 5000 Logix Designer software may allow a key to be discovered. This key is used to verify Logix controllers are communicating with Rockwell Automation design software. If successfully exploited, this vulnerability could allow an unauthorized application to connect with Logix controllers. To leverage this vulnerability, an unauthorized user would require network access to the controller.

CWE-522
Refssupport.rockwellautomation.comcisa.govnvd.nist.gov
Federal remediation due 2026-03-26
CVE-2021-30116
2021-11-03
Kaseya Virtual System/Server Administrator (VSA) Information Disclosure VulnerabilityRansomware
Kaseya

Kaseya Virtual System/Server Administrator (VSA) contains an information disclosure vulnerability allowing an attacker to obtain the sessionId that can be used to execute further attacks against the system.

CWE-522
Refsnvd.nist.gov
Federal remediation due 2021-11-17
CVE-2020-29583
2021-11-03
Zyxel Multiple Products Use of Hard-Coded Credentials Vulnerability
Zyxel

Zyxel firewalls (ATP, USG, VM) and AP Controllers (NXC2500 and NXC5500) contain a use of hard-coded credentials vulnerability in an undocumented account ("zyfwp") with an unchangeable password.

CWE-522
Refsnvd.nist.gov
Federal remediation due 2022-05-03
CVE-2017-9248
2021-11-03
Progress Telerik UI for ASP.NET AJAX and Sitefinity Cryptographic Weakness Vulnerability
Progress

Progress Telerik UI for ASP.NET AJAX and Sitefinity have a cryptographic weakness in Telerik.Web.UI.dll that can be exploited to disclose encryption keys (Telerik.Web.UI.DialogParametersEncryptionKey and/or the MachineKey), perform cross-site-scripting (XSS) attacks, compromise the ASP.NET ViewState, and/or upload and download files.

CWE-522
Refsnvd.nist.gov
Federal remediation due 2022-05-03