Rosetta Intel
Datasets/KEV CatalogThreat Actors
Rosetta Lab ↗Blur Horizon LLC
Datasets

KEV Catalog

CISA, queryable

Known exploited vulnerabilities as a queryable table — by CVE, vendor or product.

1676 entries·352 Ransomware·Updated 2026-08-25

CWE-95Definition on MITRE ↗Clear

6 results

CVE-2026-33017
2026-03-25
Langflow Code Injection Vulnerability
Langflow

Langflow contains a code injection vulnerability that could allow building public flows without requiring authentication.

CWE-94 · Code injectionCWE-95CWE-306 · Missing authentication
Refsgithub.comnvd.nist.gov
Federal remediation due 2026-04-08
CVE-2025-24893
2025-10-30
XWiki Platform Eval Injection Vulnerability
XWiki

XWiki Platform contains an eval injection vulnerability that could allow any guest to perform arbitrary remote code execution through a request to SolrSearch.

CWE-95
Refsgithub.comnvd.nist.gov
Federal remediation due 2025-11-20
CVE-2024-36401
2024-07-15
OSGeo GeoServer GeoTools Eval Injection Vulnerability
OSGeo

OSGeo GeoServer GeoTools contains an improper neutralization of directives in dynamically evaluated code vulnerability due to unsafely evaluating property names as XPath expressions. This allows unauthenticated attackers to conduct remote code execution via specially crafted input.

CWE-95
RefsThis vulnerability affects an open-source component, third-party library, or a protocol used by different products. For more information, please seenvd.nist.gov
Federal remediation due 2024-08-05
CVE-2023-7101
2024-01-02
Spreadsheet::ParseExcel Remote Code Execution Vulnerability
Spreadsheet::ParseExcel

Spreadsheet::ParseExcel contains a remote code execution vulnerability due to passing unvalidated input from a file into a string-type “eval”. Specifically, the issue stems from the evaluation of Number format strings within the Excel parsing logic.

CWE-95
RefsThis vulnerability affects a common open-source component, third-party library, or a protocol used by different products. Please check with specific vendors for information on patching status. For more information, please seenvd.nist.gov
Federal remediation due 2024-01-23
CVE-2021-22204
2021-11-17
ExifTool Remote Code Execution Vulnerability
Perl

Improper neutralization of user data in the DjVu file format in Exiftool versions 7.44 and up allows arbitrary code execution when parsing the malicious image

CWE-95
Refsnvd.nist.gov
Federal remediation due 2021-12-01
CVE-2021-22205
2021-11-03
GitLab Community and Enterprise Editions Remote Code Execution VulnerabilityRansomware
GitLab

GitHub Community and Enterprise Editions that utilize the ability to upload images through GitLab Workhorse are vulnerable to remote code execution. Workhorse passes image file extensions through ExifTool, which improperly validates the image files.

CWE-20 · Improper input validationCWE-95
Refsnvd.nist.gov
Federal remediation due 2021-11-17