Rosetta Intel
Datasets/KEV CatalogThreat Actors
Rosetta Lab ↗Blur Horizon LLC
Datasets

KEV Catalog

CISA, queryable

Known exploited vulnerabilities as a queryable table — by CVE, vendor or product.

1676 entries·352 Ransomware·Updated 2026-08-25

CWE-88Definition on MITRE ↗Clear

4 results

CVE-2026-24061
2026-01-26
GNU InetUtils Argument Injection Vulnerability
GNU

GNU InetUtils contains an argument injection vulnerability in telnetd that could allow for remote authentication bypass via a "-f root" value for the USER environment variable.

CWE-88
RefsThis vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please seecodeberg.orgcodeberg.orgnvd.nist.gov
Federal remediation due 2026-02-16
CVE-2016-10033
2025-07-07
PHPMailer Command Injection Vulnerability
PHP

PHPMailer contains a command injection vulnerability because it fails to sanitize user-supplied input. Specifically, this issue affects the 'mail()' function of 'class.phpmailer.php' script. An attacker can exploit this issue to execute arbitrary code within the context of the application. Failed exploit attempts will result in a denial-of-service condition.

CWE-77 · Command injectionCWE-88
RefsThis vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please seegithub.comnvd.nist.gov
Federal remediation due 2025-07-28
CVE-2024-41710
2025-02-12
Mitel SIP Phones Argument Injection Vulnerability
Mitel

Mitel 6800 Series, 6900 Series, and 6900w Series SIP Phones, including the 6970 Conference Unit, contain an argument injection vulnerability due to insufficient parameter sanitization during the boot process. Successful exploitation may allow an attacker to execute arbitrary commands within the context of the system.

CWE-88
Refsmitel.comnvd.nist.gov
Federal remediation due 2025-03-05
CVE-2022-36804
2022-09-30
Atlassian Bitbucket Server and Data Center Command Injection Vulnerability
Atlassian

Multiple API endpoints of Atlassian Bitbucket Server and Data Center contain a command injection vulnerability where an attacker with access to a public Bitbucket repository, or with read permissions to a private one, can execute code by sending a malicious HTTP request.

CWE-78 · OS command injectionCWE-88CWE-158
Refsjira.atlassian.comnvd.nist.gov
Federal remediation due 2022-10-21