Rosetta Intel
Datasets/KEV CatalogThreat ActorsAttack Surface
Rosetta Lab ↗Blur Horizon LLC
Datasets

KEV Catalog

CISA, queryable

Known exploited vulnerabilities as a queryable table — by CVE, vendor or product.

1685 entries·352 Ransomware·Updated 2026-08-27

1685 results·Page 13 / 34

CVE-2021-36380
2024-03-05
Sunhillo SureLine OS Command Injection Vulnerablity
Sunhillo

Sunhillo SureLine contains an OS command injection vulnerability that allows an attacker to cause a denial-of-service or utilize the device for persistence on the network via shell metacharacters in ipAddr or dnsAddr in /cgi/networkDiag.cgi.

CWE-78 · OS command injection
Refssunhillo.comnvd.nist.gov
Federal remediation due 2024-03-26
CVE-2024-21338
2024-03-04
Microsoft Windows Kernel Exposed IOCTL with Insufficient Access Control VulnerabilityRansomware
Microsoft

Microsoft Windows Kernel contains an exposed IOCTL with insufficient access control vulnerability within the IOCTL (input and output control) dispatcher in appid.sys that allows a local attacker to achieve privilege escalation.

CWE-822
Refsmsrc.microsoft.comnvd.nist.gov
Federal remediation due 2024-03-25
CVE-2023-29360
2024-02-29
Microsoft Streaming Service Untrusted Pointer Dereference Vulnerability
Microsoft

Microsoft Streaming Service contains an untrusted pointer dereference vulnerability that allows for privilege escalation, enabling a local attacker to gain SYSTEM privileges.

CWE-822
Refsmsrc.microsoft.comnvd.nist.gov
Federal remediation due 2024-03-21
CVE-2024-1709
2024-02-22
ConnectWise ScreenConnect Authentication Bypass VulnerabilityRansomware
ConnectWise

ConnectWise ScreenConnect contains an authentication bypass vulnerability that allows an attacker with network access to the management interface to create a new, administrator-level account on affected devices.

CWE-288 · Authentication bypass
Refsconnectwise.comnvd.nist.gov
Federal remediation due 2024-02-29
CVE-2024-21410
2024-02-15
Microsoft Exchange Server Privilege Escalation Vulnerability
Microsoft

Microsoft Exchange Server contains an unspecified vulnerability that allows for privilege escalation.

CWE-287 · Improper authentication
Refsmsrc.microsoft.comnvd.nist.gov
Federal remediation due 2024-03-07
CVE-2020-3259
2024-02-15
Cisco ASA and FTD Information Disclosure VulnerabilityRansomware
Cisco / Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD)

Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) contain an information disclosure vulnerability. An attacker could retrieve memory contents on an affected device, which could lead to the disclosure of confidential information due to a buffer tracking issue when the software parses invalid URLs that are requested from the web services interface. This vulnerability affects only specific AnyConnect and WebVPN configurations.

CWE-200 · Information exposure
Refstools.cisco.comnvd.nist.gov
Federal remediation due 2024-03-07
CVE-2024-21412
2024-02-13
Microsoft Windows Internet Shortcut Files Security Feature Bypass VulnerabilityRansomware
Microsoft

Microsoft Windows Internet Shortcut Files contains an unspecified vulnerability that allows for a security feature bypass.

CWE-693
Refsmsrc.microsoft.comnvd.nist.gov
Federal remediation due 2024-03-05
CVE-2024-21351
2024-02-13
Microsoft Windows SmartScreen Security Feature Bypass Vulnerability
Microsoft

Microsoft Windows SmartScreen contains a security feature bypass vulnerability that allows an attacker to bypass the SmartScreen user experience and inject code to potentially gain code execution, which could lead to some data exposure, lack of system availability, or both.

CWE-94 · Code injection
Refsmsrc.microsoft.comnvd.nist.gov
Federal remediation due 2024-03-05
CVE-2023-43770
2024-02-12
Roundcube Webmail Persistent Cross-Site Scripting (XSS) Vulnerability
Roundcube

Roundcube Webmail contains a persistent cross-site scripting (XSS) vulnerability that can lead to information disclosure via malicious link references in plain/text messages.

CWE-79 · Cross-site scripting
Refsroundcube.netnvd.nist.gov
Federal remediation due 2024-03-04
CVE-2024-21762
2024-02-09
Fortinet FortiOS Out-of-Bound Write VulnerabilityRansomware
Fortinet

Fortinet FortiOS contains an out-of-bound write vulnerability that allows a remote unauthenticated attacker to execute code or commands via specially crafted HTTP requests.

CWE-787 · Out-of-bounds write
Refsfortiguard.fortinet.comnvd.nist.gov
Federal remediation due 2024-02-16
CVE-2023-4762
2024-02-06
Google Chromium V8 Type Confusion Vulnerability
Google

Google Chromium V8 contains a type confusion vulnerability that allows a remote attacker to execute code via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

CWE-843 · Type confusion
Refschromereleases.googleblog.comnvd.nist.gov
Federal remediation due 2024-02-27
CVE-2024-21893
2024-01-31
Ivanti Connect Secure, Policy Secure, and Neurons Server-Side Request Forgery (SSRF) VulnerabilityRansomware
Ivanti

Ivanti Connect Secure (ICS, formerly known as Pulse Connect Secure), Ivanti Policy Secure, and Ivanti Neurons contain a server-side request forgery (SSRF) vulnerability in the SAML component that allows an attacker to access certain restricted resources without authentication.

CWE-918 · Server-side request forgery
Refsforums.ivanti.comnvd.nist.gov
Federal remediation due 2024-02-02
CVE-2022-48618
2024-01-31
Apple Multiple Products Memory Corruption Vulnerability
Apple

Apple iOS, iPadOS, macOS, tvOS, and watchOS contain a time-of-check/time-of-use (TOCTOU) memory corruption vulnerability that allows an attacker with read and write capabilities to bypass Pointer Authentication.

CWE-367
Refssupport.apple.comnvd.nist.gov
Federal remediation due 2024-02-21
CVE-2023-22527
2024-01-24
Atlassian Confluence Data Center and Server Template Injection VulnerabilityRansomware
Atlassian

Atlassian Confluence Data Center and Server contain an unauthenticated OGNL template injection vulnerability that can lead to remote code execution.

CWE-74
Refsconfluence.atlassian.comnvd.nist.gov
Federal remediation due 2024-02-14
CVE-2024-23222
2024-01-23
Apple Multiple Products WebKit Type Confusion Vulnerability
Apple

Apple iOS, iPadOS, macOS, tvOS, and Safari WebKit contain a type confusion vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing.

CWE-843 · Type confusion
Refssupport.apple.comnvd.nist.gov
Federal remediation due 2024-02-13
CVE-2023-34048
2024-01-22
VMware vCenter Server Out-of-Bounds Write Vulnerability
VMware

VMware vCenter Server contains an out-of-bounds write vulnerability in the implementation of the DCERPC protocol that allows an attacker to conduct remote code execution.

CWE-787 · Out-of-bounds write
Refsvmware.comnvd.nist.gov
Federal remediation due 2024-02-12
CVE-2023-35082
2024-01-18
Ivanti Endpoint Manager Mobile (EPMM) and MobileIron Core Authentication Bypass VulnerabilityRansomware
Ivanti

Ivanti Endpoint Manager Mobile (EPMM) and MobileIron Core contain an authentication bypass vulnerability that allows unauthorized users to access restricted functionality or resources of the application.

CWE-287 · Improper authentication
Refsforums.ivanti.comnvd.nist.gov
Federal remediation due 2024-02-08
CVE-2024-0519
2024-01-17
Google Chromium V8 Out-of-Bounds Memory Access Vulnerability
Google

Google Chromium V8 Engine contains an out-of-bounds memory access vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

CWE-787 · Out-of-bounds write
Refschromereleases.googleblog.comnvd.nist.gov
Federal remediation due 2024-02-07
CVE-2023-6549
2024-01-17
Citrix NetScaler ADC and NetScaler Gateway Buffer Overflow Vulnerability
Citrix

Citrix NetScaler ADC and NetScaler Gateway contain a buffer overflow vulnerability that allows for a denial-of-service when configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server.

CWE-119 · Memory buffer bounds
Refssupport.citrix.comnvd.nist.gov
Federal remediation due 2024-02-07
CVE-2023-6548
2024-01-17
Citrix NetScaler ADC and NetScaler Gateway Code Injection Vulnerability
Citrix

Citrix NetScaler ADC and NetScaler Gateway contain a code injection vulnerability that allows for authenticated remote code execution on the management interface with access to NSIP, CLIP, or SNIP.

CWE-94 · Code injection
Refssupport.citrix.comnvd.nist.gov
Federal remediation due 2024-01-24
CVE-2018-15133
2024-01-16
Laravel Deserialization of Untrusted Data Vulnerability
Laravel / Laravel Framework

Laravel Framework contains a deserialization of untrusted data vulnerability, allowing for remote command execution. This vulnerability may only be exploited if a malicious user has accessed the application encryption key (APP_KEY environment variable).

CWE-502 · Deserialization of untrusted data
Refslaravel.comnvd.nist.gov
Federal remediation due 2024-02-06
CVE-2024-21887
2024-01-10
Ivanti Connect Secure and Policy Secure Command Injection VulnerabilityRansomware
Ivanti

Ivanti Connect Secure (ICS, formerly known as Pulse Connect Secure) and Ivanti Policy Secure contain a command injection vulnerability in the web components of these products, which can allow an authenticated administrator to send crafted requests to execute code on affected appliances. This vulnerability can be leveraged in conjunction with CVE-2023-46805, an authenticated bypass issue.

CWE-77 · Command injection
RefsPlease apply mitigations per vendor instructions. For more information, please seenvd.nist.gov
Federal remediation due 2024-01-22
CVE-2023-46805
2024-01-10
Ivanti Connect Secure and Policy Secure Authentication Bypass VulnerabilityRansomware
Ivanti

Ivanti Connect Secure (ICS, formerly known as Pulse Connect Secure) and Ivanti Policy Secure gateways contain an authentication bypass vulnerability in the web component that allows an attacker to access restricted resources by bypassing control checks. This vulnerability can be leveraged in conjunction with CVE-2024-21887, a command injection vulnerability.

CWE-287 · Improper authentication
RefsPlease apply mitigations per vendor instructions. For more information, please seenvd.nist.gov
Federal remediation due 2024-01-22
CVE-2023-29357
2024-01-10
Microsoft SharePoint Server Privilege Escalation VulnerabilityRansomware
Microsoft

Microsoft SharePoint Server contains an unspecified vulnerability that allows an unauthenticated attacker, who has gained access to spoofed JWT authentication tokens, to use them for executing a network attack. This attack bypasses authentication, enabling the attacker to gain administrator privileges.

CWE-303
Refsmsrc.microsoft.comnvd.nist.gov
Federal remediation due 2024-01-31
CVE-2023-41990
2024-01-08
Apple Multiple Products Code Execution Vulnerability
Apple

Apple iOS, iPadOS, macOS, tvOS, and watchOS contain an unspecified vulnerability that allows for code execution when processing a font file.

Refssupport.apple.comnvd.nist.gov
Federal remediation due 2024-01-29
CVE-2023-38203
2024-01-08
Adobe ColdFusion Deserialization of Untrusted Data VulnerabilityRansomware
Adobe

Adobe ColdFusion contains a deserialization of untrusted data vulnerability that allows for code execution.

CWE-502 · Deserialization of untrusted data
Refshelpx.adobe.comnvd.nist.gov
Federal remediation due 2024-01-29
CVE-2023-29300
2024-01-08
Adobe ColdFusion Deserialization of Untrusted Data VulnerabilityRansomware
Adobe

Adobe ColdFusion contains a deserialization of untrusted data vulnerability that allows for code execution.

CWE-502 · Deserialization of untrusted data
Refshelpx.adobe.comnvd.nist.gov
Federal remediation due 2024-01-29
CVE-2023-27524
2024-01-08
Apache Superset Insecure Default Initialization of Resource Vulnerability
Apache

Apache Superset contains an insecure default initialization of a resource vulnerability that allows an attacker to authenticate and access unauthorized resources on installations that have not altered the default configured SECRET_KEY according to installation instructions.

CWE-1188
Refslists.apache.orgnvd.nist.gov
Federal remediation due 2024-01-29
CVE-2023-23752
2024-01-08
Joomla! Improper Access Control Vulnerability
Joomla!

Joomla! contains an improper access control vulnerability that allows unauthorized access to webservice endpoints.

CWE-284 · Improper access control
Refsdeveloper.joomla.orgnvd.nist.gov
Federal remediation due 2024-01-29
CVE-2016-20017
2024-01-08
D-Link DSL-2750B Devices Command Injection Vulnerability
D-Link

D-Link DSL-2750B devices contain a command injection vulnerability that allows remote, unauthenticated command injection via the login.cgi cli parameter.

CWE-77 · Command injection
Refssupportannouncement.us.dlink.comnvd.nist.gov
Federal remediation due 2024-01-29
CVE-2023-7101
2024-01-02
Spreadsheet::ParseExcel Remote Code Execution Vulnerability
Spreadsheet::ParseExcel

Spreadsheet::ParseExcel contains a remote code execution vulnerability due to passing unvalidated input from a file into a string-type “eval”. Specifically, the issue stems from the evaluation of Number format strings within the Excel parsing logic.

CWE-95
RefsThis vulnerability affects a common open-source component, third-party library, or a protocol used by different products. Please check with specific vendors for information on patching status. For more information, please seenvd.nist.gov
Federal remediation due 2024-01-23
CVE-2023-7024
2024-01-02
Google Chromium WebRTC Heap Buffer Overflow Vulnerability
Google

Google Chromium WebRTC, an open-source project providing web browsers with real-time communication, contains a heap buffer overflow vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could impact web browsers using WebRTC, including but not limited to Google Chrome.

CWE-787 · Out-of-bounds write
RefsThis vulnerability affects a common open-source component, third-party library, or a protocol used by different products. Please check with specific vendors for information on patching status. For more information, please seenvd.nist.gov
Federal remediation due 2024-01-23
CVE-2023-49897
2023-12-21
FXC AE1021, AE1021PE OS Command Injection Vulnerability
FXC

FXC AE1021 and AE1021PE contain an OS command injection vulnerability that allows authenticated users to execute commands via a network.

CWE-78 · OS command injection
Refsfxc.jpnvd.nist.gov
Federal remediation due 2024-01-11
CVE-2023-47565
2023-12-21
QNAP VioStor NVR OS Command Injection Vulnerability
QNAP

QNAP VioStar NVR contains an OS command injection vulnerability that allows authenticated users to execute commands via a network.

CWE-78 · OS command injection
Refsqnap.comnvd.nist.gov
Federal remediation due 2024-01-11
CVE-2023-6448
2023-12-11
Unitronics Vision PLC and HMI Insecure Default Password Vulnerability
Unitronics

Unitronics Vision Series PLCs and HMIs ship with an insecure default password, which if left unchanged, can allow attackers to execute remote commands.

CWE-1188
RefsNote that while it is possible to change the default password, implementors are encouraged to remove affected controllers from public networks and update the affected firmwarenvd.nist.gov
Federal remediation due 2023-12-18
CVE-2023-41266
2023-12-07
Qlik Sense Path Traversal VulnerabilityRansomware
Qlik

Qlik Sense contains a path traversal vulnerability that allows a remote, unauthenticated attacker to create an anonymous session by sending maliciously crafted HTTP requests. This anonymous session could allow the attacker to send further requests to unauthorized endpoints.

CWE-20 · Improper input validation
Refscommunity.qlik.comnvd.nist.gov
Federal remediation due 2023-12-28
CVE-2023-41265
2023-12-07
Qlik Sense HTTP Tunneling VulnerabilityRansomware
Qlik

Qlik Sense contains an HTTP tunneling vulnerability that allows an attacker to escalate privileges and execute HTTP requests on the backend server hosting the software.

CWE-444
Refscommunity.qlik.comnvd.nist.gov
Federal remediation due 2023-12-28
CVE-2023-33107
2023-12-05
Qualcomm Multiple Chipsets Integer Overflow Vulnerability
Qualcomm

Multiple Qualcomm chipsets contain an integer overflow vulnerability due to memory corruption in Graphics Linux while assigning shared virtual memory region during IOCTL call.

CWE-190 · Integer overflow
RefsThis vulnerability affects a common open-source component, third-party library, or a protocol used by different products. Please check with specific vendors for information on patching status. For more information, please seenvd.nist.gov
Federal remediation due 2023-12-26
CVE-2023-33106
2023-12-05
Qualcomm Multiple Chipsets Use of Out-of-Range Pointer Offset Vulnerability
Qualcomm

Multiple Qualcomm chipsets contain a use of out-of-range pointer offset vulnerability due to memory corruption in Graphics while submitting a large list of sync points in an AUX command to the IOCTL_KGSL_GPU_AUX_COMMAND.

CWE-823
RefsThis vulnerability affects a common open-source component, third-party library, or a protocol used by different products. Please check with specific vendors for information on patching status. For more information, please seenvd.nist.gov
Federal remediation due 2023-12-26
CVE-2023-33063
2023-12-05
Qualcomm Multiple Chipsets Use-After-Free Vulnerability
Qualcomm

Multiple Qualcomm chipsets contain a use-after-free vulnerability due to memory corruption in DSP Services during a remote call from HLOS to DSP.

CWE-416 · Use after free
RefsThis vulnerability affects a common open-source component, third-party library, or a protocol used by different products. Please check with specific vendors for information on patching status. For more information, please seenvd.nist.gov
Federal remediation due 2023-12-26
CVE-2022-22071
2023-12-05
Qualcomm Multiple Chipsets Use-After-Free Vulnerability
Qualcomm

Multiple Qualcomm chipsets contain a use-after-free vulnerability when process shell memory is freed using IOCTL munmap call and process initialization is in progress.

CWE-416 · Use after free
RefsThis vulnerability affects a common open-source component, third-party library, or a protocol used by different products. Please check with specific vendors for information on patching status. For more information, please seenvd.nist.gov
Federal remediation due 2023-12-26
CVE-2023-42917
2023-12-04
Apple Multiple Products WebKit Memory Corruption Vulnerability
Apple

Apple iOS, iPadOS, macOS, and Safari WebKit contain a memory corruption vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing.

CWE-787 · Out-of-bounds write
Refssupport.apple.comnvd.nist.gov
Federal remediation due 2023-12-25
CVE-2023-42916
2023-12-04
Apple Multiple Products WebKit Out-of-Bounds Read Vulnerability
Apple

Apple iOS, iPadOS, macOS, and Safari WebKit contain an out-of-bounds read vulnerability that may disclose sensitive information when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing.

CWE-125 · Out-of-bounds read
Refssupport.apple.comnvd.nist.gov
Federal remediation due 2023-12-25
CVE-2023-6345
2023-11-30
Google Skia Integer Overflow Vulnerability
Google / Chromium Skia

Google Chromium Skia contains an integer overflow vulnerability that allows a remote attacker, who has compromised the renderer process, to potentially perform a sandbox escape via a malicious file. This vulnerability affects Google Chrome and ChromeOS, Android, Flutter, and possibly other products.

CWE-190 · Integer overflow
RefsThis vulnerability affects a common open-source component, third-party library, or a protocol used by different products. Please check with specific vendors for information on patching status. For more information, please seenvd.nist.gov
Federal remediation due 2023-12-21
CVE-2023-49103
2023-11-30
ownCloud graphapi Information Disclosure Vulnerability
ownCloud

ownCloud graphapi contains an information disclosure vulnerability that can reveal sensitive data stored in phpinfo() via GetPhpInfo.php, including administrative credentials.

Refsowncloud.comnvd.nist.gov
Federal remediation due 2023-12-21
CVE-2023-4911
2023-11-21
GNU C Library Buffer Overflow Vulnerability
GNU

GNU C Library's dynamic loader ld.so contains a buffer overflow vulnerability when processing the GLIBC_TUNABLES environment variable, allowing a local attacker to execute code with elevated privileges.

CWE-122 · Heap buffer overflow
RefsThis vulnerability affects a common open-source component, third-party library, or a protocol used by different products. Please check with specific vendors for information on patching status. For more information, please seeh=1056e5b4c3f2d90ed2b4a55f96add28da2f4c8fa,nvd.nist.gov
Federal remediation due 2023-12-12
CVE-2023-36584
2023-11-16
Microsoft Windows Mark of the Web (MOTW) Security Feature Bypass Vulnerability
Microsoft

Microsoft Windows Mark of the Web (MOTW) contains a security feature bypass vulnerability resulting in a limited loss of integrity and availability of security features.

Refsmsrc.microsoft.comnvd.nist.gov
Federal remediation due 2023-12-07
CVE-2023-1671
2023-11-16
Sophos Web Appliance Command Injection Vulnerability
Sophos

Sophos Web Appliance contains a command injection vulnerability in the warn-proceed handler that allows for remote code execution.

CWE-77 · Command injection
Refssophos.comnvd.nist.gov
Federal remediation due 2023-12-07
CVE-2020-2551
2023-11-16
Oracle Fusion Middleware Unspecified Vulnerability
Oracle

Oracle Fusion Middleware contains an unspecified vulnerability in the WLS Core Components that allows an unauthenticated attacker with network access via IIOP to compromise the WebLogic Server.

Refsoracle.comnvd.nist.gov
Federal remediation due 2023-12-07
CVE-2023-36036
2023-11-14
Microsoft Windows Cloud Files Mini Filter Driver Privilege Escalation Vulnerability
Microsoft

Microsoft Windows Cloud Files Mini Filter Driver contains a privilege escalation vulnerability that could allow an attacker to gain SYSTEM privileges.

CWE-122 · Heap buffer overflow
Refsmsrc.microsoft.comnvd.nist.gov
Federal remediation due 2023-12-05
Prev13 / 34Next