Rosetta Intel
Datasets/KEV CatalogThreat ActorsAttack Surface
Rosetta Lab ↗Blur Horizon LLC
Datasets

KEV Catalog

CISA, queryable

Known exploited vulnerabilities as a queryable table — by CVE, vendor or product.

1685 entries·352 Ransomware·Updated 2026-08-27

1685 results·Page 12 / 34

CVE-2012-4792
2024-07-23
Microsoft Internet Explorer Use-After-Free Vulnerability
Microsoft

Microsoft Internet Explorer contains a use-after-free vulnerability that allows a remote attacker to execute arbitrary code via a crafted web site that triggers access to an object that (1) was not properly allocated or (2) is deleted, as demonstrated by a CDwnBindInfo object.

CWE-416 · Use after free
Refslearn.microsoft.comnvd.nist.gov
Federal remediation due 2024-08-13
CVE-2024-34102
2024-07-17
Adobe Commerce and Magento Open Source Improper Restriction of XML External Entity Reference (XXE) Vulnerability
Adobe

Adobe Commerce and Magento Open Source contain an improper restriction of XML external entity reference (XXE) vulnerability that allows for remote code execution.

CWE-611
Refshelpx.adobe.comnvd.nist.gov
Federal remediation due 2024-08-07
CVE-2024-28995
2024-07-17
SolarWinds Serv-U Path Traversal Vulnerability
SolarWinds

SolarWinds Serv-U contains a path traversal vulnerability that allows an attacker access to read sensitive files on the host machine.

CWE-22 · Path traversal
Refssolarwinds.comnvd.nist.gov
Federal remediation due 2024-08-07
CVE-2022-22948
2024-07-17
VMware vCenter Server Incorrect Default File Permissions Vulnerability
VMware

VMware vCenter Server contains an incorrect default file permissions vulnerability that allows a remote, privileged attacker to gain access to sensitive information.

CWE-276
Refsvmware.comnvd.nist.gov
Federal remediation due 2024-08-07
CVE-2024-36401
2024-07-15
OSGeo GeoServer GeoTools Eval Injection Vulnerability
OSGeo

OSGeo GeoServer GeoTools contains an improper neutralization of directives in dynamically evaluated code vulnerability due to unsafely evaluating property names as XPath expressions. This allows unauthenticated attackers to conduct remote code execution via specially crafted input.

CWE-95
RefsThis vulnerability affects an open-source component, third-party library, or a protocol used by different products. For more information, please seenvd.nist.gov
Federal remediation due 2024-08-05
CVE-2024-38112
2024-07-09
Microsoft Windows MSHTML Platform Spoofing Vulnerability
Microsoft

Microsoft Windows MSHTML Platform contains a spoofing vulnerability that has a high impact to confidentiality, integrity, and availability.

CWE-451
Refsmsrc.microsoft.comnvd.nist.gov
Federal remediation due 2024-07-30
CVE-2024-38080
2024-07-09
Microsoft Windows Hyper-V Privilege Escalation Vulnerability
Microsoft

Microsoft Windows Hyper-V contains a privilege escalation vulnerability that allows a local attacker with user permissions to gain SYSTEM privileges.

CWE-190 · Integer overflow
Refsmsrc.microsoft.comnvd.nist.gov
Federal remediation due 2024-07-30
CVE-2024-23692
2024-07-09
Rejetto HTTP File Server Improper Neutralization of Special Elements Used in a Template Engine VulnerabilityRansomware
Rejetto

Rejetto HTTP File Server contains an improper neutralization of special elements used in a template engine vulnerability. This allows a remote, unauthenticated attacker to execute commands on the affected system by sending a specially crafted HTTP request.

CWE-1336
RefsThe patched Rejetto HTTP File Server (HFS) is version 3nvd.nist.gov
Federal remediation due 2024-07-30
CVE-2024-20399
2024-07-02
Cisco NX-OS Command Injection Vulnerability
Cisco

Cisco NX-OS contains a command injection vulnerability in the command line interface (CLI) that could allow an authenticated, local attacker to execute commands as root on the underlying operating system of an affected device.

CWE-78 · OS command injection
Refssec.cloudapps.cisco.comnvd.nist.gov
Federal remediation due 2024-07-23
CVE-2022-2586
2024-06-26
Linux Kernel Use-After-Free Vulnerability
Linux

Linux Kernel contains a use-after-free vulnerability in the nft_object, allowing local attackers to escalate privileges.

CWE-416 · Use after free
RefsThis vulnerability affects a common open-source component, third-party library, or a protocol used by different products. For more information, please seenvd.nist.gov
Federal remediation due 2024-07-17
CVE-2022-24816
2024-06-26
OSGeo GeoServer JAI-EXT Code Injection Vulnerability
OSGeo

OSGeo GeoServer JAI-EXT contains a code injection vulnerability that, when programs use jt-jiffle and allow Jiffle script to be provided via network request, could allow remote code execution.

CWE-94 · Code injection
RefsThis vulnerability affects a common open-source component, third-party library, or a protocol used by different products. The patched JAI-EXT is version 1.1.22nvd.nist.gov
Federal remediation due 2024-07-17
CVE-2020-13965
2024-06-26
Roundcube Webmail Cross-Site Scripting (XSS) Vulnerability
Roundcube

Roundcube Webmail contains a cross-site scripting (XSS) vulnerability that allows a remote attacker to manipulate data via a malicious XML attachment.

CWE-80
Refsroundcube.netnvd.nist.gov
Federal remediation due 2024-07-17
CVE-2024-4358
2024-06-13
Progress Telerik Report Server Authentication Bypass by Spoofing Vulnerability
Progress

Progress Telerik Report Server contains an authorization bypass by spoofing vulnerability that allows an attacker to obtain unauthorized access.

CWE-290
Refsdocs.telerik.comnvd.nist.gov
Federal remediation due 2024-07-04
CVE-2024-32896
2024-06-13
Android Pixel Privilege Escalation Vulnerability
Android

Android Pixel contains an unspecified vulnerability in the firmware that allows for privilege escalation.

CWE-783
Refssource.android.comnvd.nist.gov
Federal remediation due 2024-07-04
CVE-2024-26169
2024-06-13
Microsoft Windows Error Reporting Service Improper Privilege Management VulnerabilityRansomware
Microsoft

Microsoft Windows Error Reporting Service contains an improper privilege management vulnerability that allows a local attacker with user permissions to gain SYSTEM privileges.

CWE-269 · Improper privilege management
Refsmsrc.microsoft.comnvd.nist.gov
Federal remediation due 2024-07-04
CVE-2024-4610
2024-06-12
Arm Mali GPU Kernel Driver Use-After-Free Vulnerability
Arm

Arm Bifrost and Valhall GPU kernel drivers contain a use-after-free vulnerability that allows a local, non-privileged user to make improper GPU memory processing operations to gain access to already freed memory.

CWE-416 · Use after free
Refsdeveloper.arm.comnvd.nist.gov
Federal remediation due 2024-07-03
CVE-2024-4577
2024-06-12
PHP-CGI OS Command Injection VulnerabilityRansomware
PHP Group

PHP, specifically Windows-based PHP used in CGI mode, contains an OS command injection vulnerability that allows for arbitrary code execution. This vulnerability is a patch bypass for CVE-2012-1823.

CWE-78 · OS command injection
RefsThis vulnerability affects a common open-source component, third-party library, or a protocol used by different products. Please check with specific vendors for information on patching status. For more information, please seenvd.nist.gov
Federal remediation due 2024-07-03
CVE-2017-3506
2024-06-03
Oracle WebLogic Server OS Command Injection Vulnerability
Oracle

Oracle WebLogic Server, a product within the Fusion Middleware suite, contains an OS command injection vulnerability that allows an attacker to execute arbitrary code via a specially crafted HTTP request that includes a malicious XML document.

CWE-78 · OS command injection
Refsoracle.comnvd.nist.gov
Federal remediation due 2024-06-24
CVE-2024-24919
2024-05-30
Check Point Quantum Security Gateways Information Disclosure VulnerabilityRansomware
Check Point

Check Point Quantum Security Gateways contain an unspecified information disclosure vulnerability. The vulnerability potentially allows an attacker to access information on Gateways connected to the internet, with IPSec VPN, Remote Access VPN or Mobile Access enabled. This issue affects several product lines from Check Point, including CloudGuard Network, Quantum Scalable Chassis, Quantum Security Gateways, and Quantum Spark Appliances.

CWE-200 · Information exposure
Refssupport.checkpoint.comnvd.nist.gov
Federal remediation due 2024-06-20
CVE-2024-1086
2024-05-30
Linux Kernel Use-After-Free VulnerabilityRansomware
Linux

Linux kernel contains a use-after-free vulnerability in the netfilter: nf_tables component that allows an attacker to achieve local privilege escalation.

CWE-416 · Use after free
RefsThis vulnerability affects a common open-source component, third-party library, or a protocol used by different products. Please check with specific vendors for information on patching status. For more information, please seenvd.nist.gov
Federal remediation due 2024-06-20
CVE-2024-4978
2024-05-29
Justice AV Solutions (JAVS) Viewer Installer Embedded Malicious Code Vulnerability
Justice AV Solutions

Justice AV Solutions (JAVS) Viewer installer contains a malicious version of ffmpeg.exe, named fffmpeg.exe (SHA256: 421a4ad2615941b177b6ec4ab5e239c14e62af2ab07c6df1741e2a62223223c4). When run, this creates a backdoor connection to a malicious C2 server.

CWE-506
RefsPlease follow the vendor’s instructions as outlined in the public statements atnvd.nist.gov
Federal remediation due 2024-06-19
CVE-2024-5274
2024-05-28
Google Chromium V8 Type Confusion Vulnerability
Google

Google Chromium V8 contains a type confusion vulnerability that allows a remote attacker to execute code via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

CWE-843 · Type confusion
Refschromereleases.googleblog.comnvd.nist.gov
Federal remediation due 2024-06-18
CVE-2020-17519
2024-05-23
Apache Flink Improper Access Control Vulnerability
Apache

Apache Flink contains an improper access control vulnerability that allows an attacker to read any file on the local filesystem of the JobManager through its REST interface.

CWE-552
RefsThis vulnerability affects a common open-source component, third-party library, or a protocol used by different products. Please check with specific vendors for information on patching status. For more information, please seenvd.nist.gov
Federal remediation due 2024-06-13
CVE-2024-4947
2024-05-20
Google Chromium V8 Type Confusion Vulnerability
Google

Google Chromium V8 contains a type confusion vulnerability that allows a remote attacker to execute code via a crafted HTML page.

CWE-843 · Type confusion
Refschromereleases.googleblog.comnvd.nist.gov
Federal remediation due 2024-06-10
CVE-2023-43208
2024-05-20
NextGen Healthcare Mirth Connect Deserialization of Untrusted Data VulnerabilityRansomware
NextGen Healthcare

NextGen Healthcare Mirth Connect contains a deserialization of untrusted data vulnerability that allows for unauthenticated remote code execution via a specially crafted request.

CWE-502 · Deserialization of untrusted data
RefsThis vulnerability affects a common open-source component, third-party library, or a protocol used by different products. Please check with specific vendors for information on patching status. For more information, please seenvd.nist.gov
Federal remediation due 2024-06-10
CVE-2024-4761
2024-05-16
Google Chromium V8 Out-of-Bounds Memory Write Vulnerability
Google

Google Chromium V8 Engine contains an unspecified out-of-bounds memory write vulnerability via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

CWE-787 · Out-of-bounds write
Refschromereleases.googleblog.comnvd.nist.gov
Federal remediation due 2024-06-06
CVE-2021-40655
2024-05-16
D-Link DIR-605 Router Information Disclosure Vulnerability
D-Link

D-Link DIR-605 routers contain an information disclosure vulnerability that allows attackers to obtain a username and password by forging a post request to the /getcfg.php page.

CWE-863
Refslegacy.us.dlink.comnvd.nist.gov
Federal remediation due 2024-06-06
CVE-2014-100005
2024-05-16
D-Link DIR-600 Router Cross-Site Request Forgery (CSRF) Vulnerability
D-Link

D-Link DIR-600 routers contain a cross-site request forgery (CSRF) vulnerability that allows an attacker to change router configurations by hijacking an existing administrator session.

CWE-352 · Cross-site request forgery
Refslegacy.us.dlink.comnvd.nist.gov
Federal remediation due 2024-06-06
CVE-2024-30051
2024-05-14
Microsoft DWM Core Library Privilege Escalation VulnerabilityRansomware
Microsoft

Microsoft DWM Core Library contains a privilege escalation vulnerability that allows an attacker to gain SYSTEM privileges.

CWE-122 · Heap buffer overflow
Refsmsrc.microsoft.comnvd.nist.gov
Federal remediation due 2024-06-04
CVE-2024-30040
2024-05-14
Microsoft Windows MSHTML Platform Security Feature Bypass Vulnerability
Microsoft

Microsoft Windows MSHTML Platform contains an unspecified vulnerability that allows for a security feature bypass.

CWE-20 · Improper input validation
Refsmsrc.microsoft.comnvd.nist.gov
Federal remediation due 2024-06-04
CVE-2024-4671
2024-05-13
Google Chromium Visuals Use-After-Free Vulnerability
Google

Google Chromium Visuals contains a use-after-free vulnerability that allows a remote attacker to exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

CWE-416 · Use after free
Refschromereleases.googleblog.comnvd.nist.gov
Federal remediation due 2024-06-03
CVE-2023-7028
2024-05-01
GitLab Community and Enterprise Editions Improper Access Control Vulnerability
GitLab / GitLab CE/EE

GitLab Community and Enterprise Editions contain an improper access control vulnerability. This allows an attacker to trigger password reset emails to be sent to an unverified email address to ultimately facilitate an account takeover.

CWE-284 · Improper access control
Refsabout.gitlab.comnvd.nist.gov
Federal remediation due 2024-05-22
CVE-2024-29988
2024-04-30
Microsoft SmartScreen Prompt Security Feature Bypass Vulnerability
Microsoft

Microsoft SmartScreen Prompt contains a security feature bypass vulnerability that allows an attacker to bypass the Mark of the Web (MotW) feature. This vulnerability can be chained with CVE-2023-38831 and CVE-2024-21412 to execute a malicious file.

CWE-693
Refsmsrc.microsoft.comnvd.nist.gov
Federal remediation due 2024-05-21
CVE-2024-4040
2024-04-24
CrushFTP VFS Sandbox Escape Vulnerability
CrushFTP

CrushFTP contains an unspecified sandbox escape vulnerability that allows a remote attacker to escape the CrushFTP virtual file system (VFS).

CWE-1336
Refscrushftp.comnvd.nist.gov
Federal remediation due 2024-05-01
CVE-2024-20359
2024-04-24
Cisco ASA and FTD Privilege Escalation Vulnerability
Cisco / Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD)

Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) contain a privilege escalation vulnerability that can allow local privilege escalation from Administrator to root.

CWE-94 · Code injection
Refssec.cloudapps.cisco.comnvd.nist.gov
Federal remediation due 2024-05-01
CVE-2024-20353
2024-04-24
Cisco ASA and FTD Denial of Service Vulnerability
Cisco / Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD)

Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) contain an infinite loop vulnerability that can lead to remote denial of service condition.

CWE-835
Refssec.cloudapps.cisco.comnvd.nist.gov
Federal remediation due 2024-05-01
CVE-2022-38028
2024-04-23
Microsoft Windows Print Spooler Privilege Escalation Vulnerability
Microsoft

Microsoft Windows Print Spooler service contains a privilege escalation vulnerability. An attacker may modify a JavaScript constraints file and execute it with SYSTEM-level permissions.

Refsmsrc.microsoft.comnvd.nist.gov
Federal remediation due 2024-05-14
CVE-2024-3400
2024-04-12
Palo Alto Networks PAN-OS Command Injection VulnerabilityRansomware
Palo Alto Networks

Palo Alto Networks PAN-OS GlobalProtect feature contains a command injection vulnerability that allows an unauthenticated attacker to execute commands with root privileges on the firewall.

CWE-20 · Improper input validationCWE-77 · Command injection
Refssecurity.paloaltonetworks.comnvd.nist.gov
Federal remediation due 2024-04-19
CVE-2024-3273
2024-04-11
D-Link Multiple NAS Devices Command Injection Vulnerability
D-Link

D-Link DNS-320L, DNS-325, DNS-327L, and DNS-340L contain a command injection vulnerability. When combined with CVE-2024-3272, this can lead to remote, unauthorized code execution.

CWE-77 · Command injection
Refssupportannouncement.us.dlink.comnvd.nist.gov
Federal remediation due 2024-05-02
CVE-2024-3272
2024-04-11
D-Link Multiple NAS Devices Use of Hard-Coded Credentials Vulnerability
D-Link

D-Link DNS-320L, DNS-325, DNS-327L, and DNS-340L contains a hard-coded credential that allows an attacker to conduct authenticated command injection, leading to remote, unauthorized code execution.

CWE-798 · Hard-coded credentials
Refssupportannouncement.us.dlink.comnvd.nist.gov
Federal remediation due 2024-05-02
CVE-2024-29748
2024-04-04
Android Pixel Privilege Escalation Vulnerability
Android

Android Pixel contains a privilege escalation vulnerability that allows an attacker to interrupt a factory reset triggered by a device admin app.

CWE-280
Refssource.android.comnvd.nist.gov
Federal remediation due 2024-04-25
CVE-2024-29745
2024-04-04
Android Pixel Information Disclosure Vulnerability
Android

Android Pixel contains an information disclosure vulnerability in the fastboot firmware used to support unlocking, flashing, and locking affected devices.

CWE-908
Refssource.android.comnvd.nist.gov
Federal remediation due 2024-04-25
CVE-2023-24955
2024-03-26
Microsoft SharePoint Server Code Injection VulnerabilityRansomware
Microsoft

Microsoft SharePoint Server contains a code injection vulnerability that allows an authenticated attacker with Site Owner privileges to execute code remotely.

CWE-94 · Code injection
Refsmsrc.microsoft.comnvd.nist.gov
Federal remediation due 2024-04-16
CVE-2023-48788
2024-03-25
Fortinet FortiClient EMS SQL Injection VulnerabilityRansomware
Fortinet

Fortinet FortiClient EMS contains a SQL injection vulnerability that allows an unauthenticated attacker to execute commands as SYSTEM via specifically crafted requests.

CWE-89 · SQL injection
Refsfortiguard.comnvd.nist.gov
Federal remediation due 2024-04-15
CVE-2021-44529
2024-03-25
Ivanti Endpoint Manager Cloud Service Appliance (EPM CSA) Code Injection Vulnerability Ransomware
Ivanti

Ivanti Endpoint Manager Cloud Service Appliance (EPM CSA) contains a code injection vulnerability that allows an unauthenticated user to execute malicious code with limited permissions (nobody).

CWE-94 · Code injection
Refsforums.ivanti.comnvd.nist.gov
Federal remediation due 2024-04-15
CVE-2019-7256
2024-03-25
Nice Linear eMerge E3-Series OS Command Injection Vulnerability
Nice

Nice Linear eMerge E3-Series contains an OS command injection vulnerability that allows an attacker to conduct remote code execution.

CWE-78 · OS command injection
Refslinear-solutions.comnvd.nist.gov
Federal remediation due 2024-04-15
CVE-2024-27198
2024-03-07
JetBrains TeamCity Authentication Bypass VulnerabilityRansomware
JetBrains

JetBrains TeamCity contains an authentication bypass vulnerability that allows an attacker to perform admin actions.

CWE-288 · Authentication bypass
Refsjetbrains.comblog.jetbrains.comnvd.nist.gov
Federal remediation due 2024-03-28
CVE-2024-23296
2024-03-06
Apple Multiple Products Memory Corruption Vulnerability
Apple

Apple iOS, iPadOS, macOS, tvOS, and watchOS RTKit contain a memory corruption vulnerability that allows an attacker with arbitrary kernel read and write capability to bypass kernel memory protections.

CWE-787 · Out-of-bounds write
Refssupport.apple.comnvd.nist.gov
Federal remediation due 2024-03-27
CVE-2024-23225
2024-03-06
Apple Multiple Products Memory Corruption Vulnerability
Apple

Apple iOS, iPadOS, macOS, tvOS, watchOS, and visionOS kernel contain a memory corruption vulnerability that allows an attacker with arbitrary kernel read and write capability to bypass kernel memory protections.

CWE-787 · Out-of-bounds write
Refssupport.apple.comnvd.nist.gov
Federal remediation due 2024-03-27
CVE-2023-21237
2024-03-05
Android Pixel Information Disclosure Vulnerability
Android

Android Pixel contains a vulnerability in the Framework component, where the UI may be misleading or insufficient, providing a means to hide a foreground service notification. This could enable a local attacker to disclose sensitive information.

CWE-200 · Information exposure
Refssource.android.comnvd.nist.gov
Federal remediation due 2024-03-26
Prev12 / 34Next