Rosetta Intel
Datasets/KEV CatalogThreat Actors
Rosetta Lab ↗Blur Horizon LLC
Datasets

KEV Catalog

CISA, queryable

Known exploited vulnerabilities as a queryable table — by CVE, vendor or product.

1676 entries·352 Ransomware·Updated 2026-08-25

CWE-807Definition on MITRE ↗Clear

3 results

CVE-2026-21514
2026-02-10
Microsoft Office Word Reliance on Untrusted Inputs in a Security Decision Vulnerability
Microsoft

Microsoft Office Word contains a reliance on untrusted inputs in a security decision vulnerability that could allow an authorized attacker to elevate privileges locally.

CWE-807
Refsmsrc.microsoft.comnvd.nist.gov
Federal remediation due 2026-03-03
CVE-2026-21509
2026-01-26
Microsoft Office Security Feature Bypass Vulnerability
Microsoft

Microsoft Office contains a security feature bypass vulnerability in which reliance on untrusted inputs in a security decision in Microsoft Office could allow an unauthorized attacker to bypass a security feature locally. Some of the impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). Users are advised to discontinue use and/or transition to a supported version.

CWE-807
RefsPlease adhere to Microsoft’s recommended guidelines to address this vulnerability. Implement all final mitigations provided by the vendor for Office 2021, and apply the interim corresponding mitigations for Office 2016 and Office 2019 until the final patch becomes available. For more information please seenvd.nist.gov
Federal remediation due 2026-02-16
CVE-2019-9621
2025-07-07
Synacor Zimbra Collaboration Suite (ZCS) Server-Side Request Forgery (SSRF) Vulnerability
Synacor

Synacor Zimbra Collaboration Suite (ZCS) contains a server-side request forgery (SSRF) vulnerability via the ProxyServlet component.

CWE-918 · Server-side request forgeryCWE-807
Refswiki.zimbra.comwiki.zimbra.comnvd.nist.gov
Federal remediation due 2025-07-28