Rosetta Intel
Datasets/KEV CatalogThreat Actors
Rosetta Lab ↗Blur Horizon LLC
Datasets

KEV Catalog

CISA, queryable

Known exploited vulnerabilities as a queryable table — by CVE, vendor or product.

1676 entries·352 Ransomware·Updated 2026-08-25

CWE-863Definition on MITRE ↗Clear

16 results

CVE-2025-55177
2025-09-02
Meta Platforms WhatsApp Incorrect Authorization Vulnerability
Meta Platforms

Meta Platforms WhatsApp contains an incorrect authorization vulnerability due to an incomplete authorization of linked device synchronization messages. This vulnerability could allow an unrelated user to trigger processing of content from an arbitrary URL on a target’s device.

CWE-863
Refswhatsapp.comnvd.nist.gov
Federal remediation due 2025-09-23
CVE-2025-21480
2025-06-03
Qualcomm Multiple Chipsets Incorrect Authorization Vulnerability
Qualcomm

Multiple Qualcomm chipsets contain an incorrect authorization vulnerability. This vulnerability allows for memory corruption due to unauthorized command execution in GPU micronode while executing specific sequence of commands.

CWE-863
RefsPlease check with specific vendors (OEMs,) for information on patching status. For more information, please seenvd.nist.gov
Federal remediation due 2025-06-24
CVE-2025-21479
2025-06-03
Qualcomm Multiple Chipsets Incorrect Authorization Vulnerability
Qualcomm

Multiple Qualcomm chipsets contain an incorrect authorization vulnerability. This vulnerability allows for memory corruption due to unauthorized command execution in GPU micronode while executing specific sequence of commands.

CWE-863
RefsPlease check with specific vendors (OEMs,) for information on patching status. For more information, please seenvd.nist.gov
Federal remediation due 2025-06-24
CVE-2025-24200
2025-02-12
Apple iOS and iPadOS Incorrect Authorization Vulnerability
Apple

Apple iOS and iPadOS contains an incorrect authorization vulnerability that allows a physical attacker to disable USB Restricted Mode on a locked device.

CWE-863
Refssupport.apple.comnvd.nist.gov
Federal remediation due 2025-03-05
CVE-2024-21287
2024-11-21
Oracle Agile Product Lifecycle Management (PLM) Incorrect Authorization Vulnerability
Oracle

Oracle Agile Product Lifecycle Management (PLM) contains an incorrect authorization vulnerability in the Process Extension component of the Software Development Kit. Successful exploitation of this vulnerability may result in unauthenticated file disclosure.

CWE-863
Refsoracle.comnvd.nist.gov
Federal remediation due 2024-12-12
CVE-2024-38856
2024-08-27
Apache OFBiz Incorrect Authorization Vulnerability
Apache

Apache OFBiz contains an incorrect authorization vulnerability that could allow remote code execution via a Groovy payload in the context of the OFBiz user process by an unauthenticated attacker.

CWE-863
RefsThis vulnerability affects a common open-source component, third-party library, or a protocol used by different products. Please check with specific vendors for information on patching status. For more information, please seenvd.nist.gov
Federal remediation due 2024-09-17
CVE-2021-40655
2024-05-16
D-Link DIR-605 Router Information Disclosure Vulnerability
D-Link

D-Link DIR-605 routers contain an information disclosure vulnerability that allows attackers to obtain a username and password by forging a post request to the /getcfg.php page.

CWE-863
Refslegacy.us.dlink.comnvd.nist.gov
Federal remediation due 2024-06-06
CVE-2023-22518
2023-11-07
Atlassian Confluence Data Center and Server Improper Authorization VulnerabilityRansomware
Atlassian

Atlassian Confluence Data Center and Server contain an improper authorization vulnerability that can result in significant data loss when exploited by an unauthenticated attacker. There is no impact on confidentiality since the attacker cannot exfiltrate any data.

CWE-863
Refsconfluence.atlassian.comnvd.nist.gov
Federal remediation due 2023-11-28
CVE-2023-38035
2023-08-22
Ivanti Sentry Authentication Bypass VulnerabilityRansomware
Ivanti

Ivanti Sentry, formerly known as MobileIron Sentry, contains an authentication bypass vulnerability that may allow an attacker to bypass authentication controls on the administrative interface due to an insufficiently restrictive Apache HTTPD configuration.

CWE-863
Refsforums.ivanti.comnvd.nist.gov
Federal remediation due 2023-09-12
CVE-2021-3560
2023-05-12
Red Hat Polkit Incorrect Authorization Vulnerability
Red Hat

Red Hat Polkit contains an incorrect authorization vulnerability through the bypassing of credential checks for D-Bus requests, allowing for privilege escalation.

CWE-863
Refsbugzilla.redhat.comnvd.nist.gov
Federal remediation due 2023-06-02
CVE-2023-24880
2023-03-14
Microsoft Windows SmartScreen Security Feature Bypass VulnerabilityRansomware
Microsoft

Microsoft Windows SmartScreen contains a security feature bypass vulnerability that could allow an attacker to evade Mark of the Web (MOTW) defenses via a specially crafted malicious file.

CWE-863
Refsmsrc.microsoft.comnvd.nist.gov
Federal remediation due 2023-04-04
CVE-2023-21715
2023-02-14
Microsoft Office Publisher Security Feature Bypass Vulnerability
Microsoft

Microsoft Office Publisher contains a security feature bypass vulnerability that allows for a local, authenticated attack on a targeted system.

CWE-863
Refsmsrc.microsoft.comnvd.nist.gov
Federal remediation due 2023-03-07
CVE-2022-41091
2022-11-08
Microsoft Windows Mark of the Web (MOTW) Security Feature Bypass VulnerabilityRansomware
Microsoft

Microsoft Windows Mark of the Web (MOTW) contains a security feature bypass vulnerability resulting in a limited loss of integrity and availability of security features.

CWE-863
Refsportal.msrc.microsoft.comnvd.nist.gov
Federal remediation due 2022-12-09
CVE-2021-30533
2022-06-27
Google Chromium PopupBlocker Security Bypass Vulnerability
Google

Google Chromium PopupBlocker contains an insufficient policy enforcement vulnerability that allows a remote attacker to bypass navigation restrictions via a crafted iframe. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

CWE-863
Refsnvd.nist.gov
Federal remediation due 2022-07-18
CVE-2019-7192
2022-06-08
QNAP Photo Station Improper Access Control VulnerabilityRansomware
QNAP

QNAP NAS devices running Photo Station contain an improper access control vulnerability allowing remote attackers to gain unauthorized access to the system.

CWE-863
Refsnvd.nist.gov
Federal remediation due 2022-06-22
CVE-2021-22986
2021-11-03
F5 BIG-IP and BIG-IQ Centralized Management iControl REST Remote Code Execution VulnerabilityRansomware
F5

F5 BIG-IP and BIG-IQ Centralized Management contain a remote code execution vulnerability in the iControl REST interface that allows unauthenticated attackers with network access to execute system commands, create or delete files, and disable services.

CWE-863
Refsnvd.nist.gov
Federal remediation due 2021-11-17