Rosetta Intel
Datasets/KEV CatalogThreat ActorsAttack Surface
Rosetta Lab ↗Blur Horizon LLC
Datasets

KEV Catalog

CISA, queryable

Known exploited vulnerabilities as a queryable table — by CVE, vendor or product.

1685 entries·352 Ransomware·Updated 2026-08-27

1685 results·Page 14 / 34

CVE-2023-36033
2023-11-14
Microsoft Windows Desktop Window Manager (DWM) Core Library Privilege Escalation Vulnerability
Microsoft

Microsoft Windows Desktop Window Manager (DWM) Core Library contains an unspecified vulnerability that allows for privilege escalation.

CWE-822
Refsmsrc.microsoft.comnvd.nist.gov
Federal remediation due 2023-12-05
CVE-2023-36025
2023-11-14
Microsoft Windows SmartScreen Security Feature Bypass Vulnerability
Microsoft

Microsoft Windows SmartScreen contains a security feature bypass vulnerability that could allow an attacker to bypass Windows Defender SmartScreen checks and their associated prompts.

Refsmsrc.microsoft.comnvd.nist.gov
Federal remediation due 2023-12-05
CVE-2023-47246
2023-11-13
SysAid Server Path Traversal VulnerabilityRansomware
SysAid

SysAid Server (on-premises version) contains a path traversal vulnerability that leads to code execution.

CWE-22 · Path traversal
Refssysaid.comnvd.nist.gov
Federal remediation due 2023-12-04
CVE-2023-36851
2023-11-13
Juniper Junos OS SRX Series Missing Authentication for Critical Function Vulnerability
Juniper

Juniper Junos OS on SRX Series contains a missing authentication for critical function vulnerability that allows an unauthenticated, network-based attacker to cause limited impact to the file system integrity. With a specific request to webauth_operation.php that doesn't require authentication, an attacker is able to upload arbitrary files via J-Web, leading to a loss of integrity for a certain part of the file system, which may allow chaining to other vulnerabilities.

CWE-306 · Missing authentication
Refssupportportal.juniper.netnvd.nist.gov
Federal remediation due 2023-11-17
CVE-2023-36847
2023-11-13
Juniper Junos OS EX Series Missing Authentication for Critical Function Vulnerability
Juniper

Juniper Junos OS on EX Series contains a missing authentication for critical function vulnerability that allows an unauthenticated, network-based attacker to cause limited impact to the file system integrity. With a specific request to installAppPackage.php that doesn't require authentication, an attacker is able to upload arbitrary files via J-Web, leading to a loss of integrity for a certain part of the file system, which may allow chaining to other vulnerabilities.

CWE-306 · Missing authentication
Refssupportportal.juniper.netnvd.nist.gov
Federal remediation due 2023-11-17
CVE-2023-36846
2023-11-13
Juniper Junos OS SRX Series Missing Authentication for Critical Function Vulnerability
Juniper

Juniper Junos OS on SRX Series contains a missing authentication for critical function vulnerability that allows an unauthenticated, network-based attacker to cause limited impact to the file system integrity. With a specific request to user.php that doesn't require authentication, an attacker is able to upload arbitrary files via J-Web, leading to a loss of integrity for a certain part of the file system, which may allow chaining to other vulnerabilities.

CWE-306 · Missing authentication
Refssupportportal.juniper.netnvd.nist.gov
Federal remediation due 2023-11-17
CVE-2023-36845
2023-11-13
Juniper Junos OS EX Series and SRX Series PHP External Variable Modification Vulnerability
Juniper

Juniper Junos OS on EX Series and SRX Series contains a PHP external variable modification vulnerability that allows an unauthenticated, network-based attacker to control an important environment variable. Using a crafted request, which sets the variable PHPRC, an attacker is able to modify the PHP execution environment allowing the injection und execution of code.

CWE-473
Refssupportportal.juniper.netnvd.nist.gov
Federal remediation due 2023-11-17
CVE-2023-36844
2023-11-13
Juniper Junos OS EX Series PHP External Variable Modification Vulnerability
Juniper

Juniper Junos OS on EX Series contains a PHP external variable modification vulnerability that allows an unauthenticated, network-based attacker to control certain, important environment variables. Using a crafted request an attacker is able to modify certain PHP environment variables, leading to partial loss of integrity, which may allow chaining to other vulnerabilities.

CWE-473
Refssupportportal.juniper.netnvd.nist.gov
Federal remediation due 2023-11-17
CVE-2023-29552
2023-11-08
Service Location Protocol (SLP) Denial-of-Service Vulnerability
IETF

The Service Location Protocol (SLP) contains a denial-of-service (DoS) vulnerability that could allow an unauthenticated, remote attacker to register services and use spoofed UDP traffic to conduct a denial-of-service (DoS) attack with a significant amplification factor.

RefsThis vulnerability affects a common open-source component, third-party library, or a protocol used by different products. Please check with specific vendors for information on the patching status. For more information please seenvd.nist.gov
Federal remediation due 2023-11-29
CVE-2023-22518
2023-11-07
Atlassian Confluence Data Center and Server Improper Authorization VulnerabilityRansomware
Atlassian

Atlassian Confluence Data Center and Server contain an improper authorization vulnerability that can result in significant data loss when exploited by an unauthenticated attacker. There is no impact on confidentiality since the attacker cannot exfiltrate any data.

CWE-863
Refsconfluence.atlassian.comnvd.nist.gov
Federal remediation due 2023-11-28
CVE-2023-46604
2023-11-02
Apache ActiveMQ Deserialization of Untrusted Data VulnerabilityRansomware
Apache

Apache ActiveMQ contains a deserialization of untrusted data vulnerability that may allow a remote attacker with network access to a broker to run shell commands by manipulating serialized class types in the OpenWire protocol to cause the broker to instantiate any class on the classpath.

CWE-502 · Deserialization of untrusted data
Refsactivemq.apache.orgnvd.nist.gov
Federal remediation due 2023-11-23
CVE-2023-46748
2023-10-31
F5 BIG-IP Configuration Utility SQL Injection Vulnerability
F5

F5 BIG-IP Configuration utility contains an SQL injection vulnerability that may allow an authenticated attacker with network access through the BIG-IP management port and/or self IP addresses to execute system commands. This vulnerability can be used in conjunction with CVE-2023-46747.

CWE-89 · SQL injection
Refsmy.f5.comnvd.nist.gov
Federal remediation due 2023-11-21
CVE-2023-46747
2023-10-31
F5 BIG-IP Configuration Utility Authentication Bypass VulnerabilityRansomware
F5

F5 BIG-IP Configuration utility contains an authentication bypass using an alternate path or channel vulnerability due to undisclosed requests that may allow an unauthenticated attacker with network access to the BIG-IP system through the management port and/or self IP addresses to execute system commands. This vulnerability can be used in conjunction with CVE-2023-46748.

CWE-288 · Authentication bypass
Refsmy.f5.comnvd.nist.gov
Federal remediation due 2023-11-21
CVE-2023-5631
2023-10-26
Roundcube Webmail Persistent Cross-Site Scripting (XSS) Vulnerability
Roundcube

Roundcube Webmail contains a persistent cross-site scripting (XSS) vulnerability that allows a remote attacker to run malicious JavaScript code.

CWE-79 · Cross-site scripting
Refsroundcube.netnvd.nist.gov
Federal remediation due 2023-11-16
CVE-2023-20273
2023-10-23
Cisco IOS XE Web UI Command Injection Vulnerability
Cisco

Cisco IOS XE contains a command injection vulnerability in the web user interface. When chained with CVE-2023-20198, the attacker can leverage the new local user to elevate privilege to root and write the implant to the file system. Cisco identified CVE-2023-20273 as the vulnerability exploited to deploy the implant. CVE-2021-1435, previously associated with the exploitation events, is no longer believed to be related to this activity.

CWE-78 · OS command injection
Refssec.cloudapps.cisco.comnvd.nist.gov
Federal remediation due 2023-10-27
CVE-2023-4966
2023-10-18
Citrix NetScaler ADC and NetScaler Gateway Buffer Overflow VulnerabilityRansomware
Citrix

Citrix NetScaler ADC and NetScaler Gateway contain a buffer overflow vulnerability that allows for sensitive information disclosure when configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server.

CWE-119 · Memory buffer bounds
Refsnetscaler.comnvd.nist.gov
Federal remediation due 2023-11-08
CVE-2023-20198
2023-10-16
Cisco IOS XE Web UI Privilege Escalation Vulnerability
Cisco

Cisco IOS XE Web UI contains a privilege escalation vulnerability in the web user interface that could allow a remote, unauthenticated attacker to create an account with privilege level 15 access. The attacker can then use that account to gain control of the affected device.

CWE-420
Refscisco.comnvd.nist.gov
Federal remediation due 2023-10-20
CVE-2023-44487
2023-10-10
HTTP/2 Rapid Reset Attack Vulnerability
IETF

HTTP/2 contains a rapid reset vulnerability that allows for a distributed denial-of-service attack (DDoS).

CWE-400
RefsThis vulnerability affects a common open-source component, third-party library, or protocol used by different products. For more information, please see: HTTP/2 Rapid Reset Vulnerability, CVE-2023-44487 | CISAblog.cloudflare.comnvd.nist.gov
Federal remediation due 2023-10-31
CVE-2023-41763
2023-10-10
Microsoft Skype for Business Privilege Escalation Vulnerability
Microsoft

Microsoft Skype for Business contains an unspecified vulnerability that allows for privilege escalation.

CWE-918 · Server-side request forgery
Refsmsrc.microsoft.comnvd.nist.gov
Federal remediation due 2023-10-31
CVE-2023-36563
2023-10-10
Microsoft WordPad Information Disclosure Vulnerability
Microsoft

Microsoft WordPad contains an unspecified vulnerability that allows for information disclosure.

CWE-20 · Improper input validation
Refsmsrc.microsoft.comnvd.nist.gov
Federal remediation due 2023-10-31
CVE-2023-21608
2023-10-10
Adobe Acrobat and Reader Use-After-Free Vulnerability
Adobe

Adobe Acrobat and Reader contains a use-after-free vulnerability that allows for code execution in the context of the current user.

CWE-416 · Use after free
Refshelpx.adobe.comnvd.nist.gov
Federal remediation due 2023-10-31
CVE-2023-20109
2023-10-10
Cisco IOS and IOS XE Group Encrypted Transport VPN Out-of-Bounds Write Vulnerability
Cisco

Cisco IOS and IOS XE contain an out-of-bounds write vulnerability in the Group Encrypted Transport VPN (GET VPN) feature that could allow an authenticated, remote attacker who has administrative control of either a group member or a key server to execute malicious code or cause a device to crash.

CWE-787 · Out-of-bounds write
Refssec.cloudapps.cisco.comnvd.nist.gov
Federal remediation due 2023-10-31
CVE-2023-42824
2023-10-05
Apple iOS and iPadOS Kernel Privilege Escalation Vulnerability
Apple

Apple iOS and iPadOS contain an unspecified vulnerability that allows for local privilege escalation.

Refssupport.apple.comnvd.nist.gov
Federal remediation due 2023-10-26
CVE-2023-40044
2023-10-05
Progress WS_FTP Server Deserialization of Untrusted Data VulnerabilityRansomware
Progress

Progress WS_FTP Server contains a deserialization of untrusted data vulnerability in the Ad Hoc Transfer module that allows an authenticated attacker to execute remote commands on the underlying operating system.

CWE-502 · Deserialization of untrusted data
Refscommunity.progress.comnvd.nist.gov
Federal remediation due 2023-10-26
CVE-2023-22515
2023-10-05
Atlassian Confluence Data Center and Server Broken Access Control VulnerabilityRansomware
Atlassian

Atlassian Confluence Data Center and Server contains a broken access control vulnerability that allows an attacker to create unauthorized Confluence administrator accounts and access Confluence.

Refsconfluence.atlassian.comnvd.nist.gov
Federal remediation due 2023-10-13
CVE-2023-42793
2023-10-04
JetBrains TeamCity Authentication Bypass VulnerabilityRansomware
JetBrains

JetBrains TeamCity contains an authentication bypass vulnerability that allows for remote code execution on TeamCity Server.

CWE-288 · Authentication bypass
Refsblog.jetbrains.comnvd.nist.gov
Federal remediation due 2023-10-25
CVE-2023-28229
2023-10-04
Microsoft Windows CNG Key Isolation Service Privilege Escalation Vulnerability
Microsoft

Microsoft Windows Cryptographic Next Generation (CNG) Key Isolation Service contains an unspecified vulnerability that allows an attacker to gain specific limited SYSTEM privileges.

CWE-591
Refsmsrc.microsoft.comnvd.nist.gov
Federal remediation due 2023-10-25
CVE-2023-4211
2023-10-03
Arm Mali GPU Kernel Driver Use-After-Free Vulnerability
Arm

Arm Mali GPU Kernel Driver contains a use-after-free vulnerability that allows a local, non-privileged user to make improper GPU memory processing operations to gain access to already freed memory.

CWE-416 · Use after free
Refsdeveloper.arm.comnvd.nist.gov
Federal remediation due 2023-10-24
CVE-2023-5217
2023-10-02
Google Chromium libvpx Heap Buffer Overflow Vulnerability
Google

Google Chromium libvpx contains a heap buffer overflow vulnerability in vp8 encoding that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could impact web browsers using libvpx, including but not limited to Google Chrome.

CWE-787 · Out-of-bounds write
Refschromereleases.googleblog.comnvd.nist.gov
Federal remediation due 2023-10-23
CVE-2018-14667
2023-09-28
Red Hat JBoss RichFaces Framework Expression Language Injection Vulnerability
Red Hat

Red Hat JBoss RichFaces Framework contains an expression language injection vulnerability via the UserResource resource. A remote, unauthenticated attacker could exploit this vulnerability to execute malicious code using a chain of Java serialized objects via org.ajax4jsf.resource.UserResource$UriData.

CWE-94 · Code injection
Refsbugzilla.redhat.comnvd.nist.gov
Federal remediation due 2023-10-19
CVE-2023-41993
2023-09-25
Apple Multiple Products WebKit Code Execution Vulnerability
Apple

Apple iOS, iPadOS, macOS, and Safari WebKit contain an unspecified vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing.

CWE-754
Refssupport.apple.comnvd.nist.gov
Federal remediation due 2023-10-16
CVE-2023-41992
2023-09-25
Apple Multiple Products Kernel Privilege Escalation Vulnerability
Apple

Apple iOS, iPadOS, macOS, and watchOS contain an unspecified vulnerability that allows for local privilege escalation.

CWE-754
Refssupport.apple.comnvd.nist.gov
Federal remediation due 2023-10-16
CVE-2023-41991
2023-09-25
Apple Multiple Products Improper Certificate Validation Vulnerability
Apple

Apple iOS, iPadOS, macOS, and watchOS contain an improper certificate validation vulnerability that can allow a malicious app to bypass signature validation.

CWE-295
Refssupport.apple.comnvd.nist.gov
Federal remediation due 2023-10-16
CVE-2023-41179
2023-09-21
Trend Micro Apex One and Worry-Free Business Security Remote Code Execution Vulnerability
Trend Micro

Trend Micro Apex One and Worry-Free Business Security contain an unspecified vulnerability in the third-party anti-virus uninstaller that could allow an attacker to manipulate the module to conduct remote code execution. An attacker must first obtain administrative console access on the target system in order to exploit this vulnerability.

Refssuccess.trendmicro.comnvd.nist.gov
Federal remediation due 2023-10-12
CVE-2023-28434
2023-09-19
MinIO Security Feature Bypass Vulnerability
MinIO

MinIO contains a security feature bypass vulnerability that allows an attacker to use crafted requests to bypass metadata bucket name checking and put an object into any bucket while processing `PostPolicyBucket` to conduct privilege escalation. To carry out this attack, the attacker requires credentials with `arn:aws:s3:::*` permission, as well as enabled Console API access.

CWE-269 · Improper privilege management
Refsgithub.comnvd.nist.gov
Federal remediation due 2023-10-10
CVE-2022-22265
2023-09-18
Samsung Mobile Devices Use-After-Free Vulnerability
Samsung

Samsung devices with selected Exynos chipsets contain a use-after-free vulnerability that allows malicious memory write and code execution.

CWE-703
Refssecurity.samsungmobile.comnvd.nist.gov
Federal remediation due 2023-10-09
CVE-2021-3129
2023-09-18
Laravel Ignition File Upload VulnerabilityRansomware
Laravel

Laravel Ignition contains a file upload vulnerability that allows unauthenticated remote attackers to execute malicious code due to insecure usage of file_get_contents() and file_put_contents().

Refsgithub.comnvd.nist.gov
Federal remediation due 2023-10-09
CVE-2017-6884
2023-09-18
Zyxel EMG2926 Routers Command Injection VulnerabilityRansomware
Zyxel

Zyxel EMG2926 routers contain a command injection vulnerability located in the diagnostic tools, specifically the nslookup function. A malicious user may exploit numerous vectors to execute malicious commands on the router, such as the ping_ip parameter to the expert/maintenance/diagnostic/nslookup URI.

CWE-78 · OS command injection
Refszyxel.comnvd.nist.gov
Federal remediation due 2023-10-09
CVE-2014-8361
2023-09-18
Realtek SDK Improper Input Validation Vulnerability
Realtek

Realtek SDK contains an improper input validation vulnerability in the miniigd SOAP service that allows remote attackers to execute malicious code via a crafted NewInternalClient request.

CWE-20 · Improper input validation
Refsweb.archive.orgnvd.nist.gov
Federal remediation due 2023-10-09
CVE-2023-26369
2023-09-14
Adobe Acrobat and Reader Out-of-Bounds Write Vulnerability
Adobe

Adobe Acrobat and Reader contains an out-of-bounds write vulnerability that allows for code execution.

CWE-787 · Out-of-bounds write
Refshelpx.adobe.comnvd.nist.gov
Federal remediation due 2023-10-05
CVE-2023-4863
2023-09-13
Google Chromium WebP Heap-Based Buffer Overflow Vulnerability
Google

Google Chromium WebP contains a heap-based buffer overflow vulnerability that allows a remote attacker to perform an out-of-bounds memory write via a crafted HTML page. This vulnerability can affect applications that use the WebP Codec.

CWE-787 · Out-of-bounds write
Refschromereleases.googleblog.comnvd.nist.gov
Federal remediation due 2023-10-04
CVE-2023-35674
2023-09-13
Android Framework Privilege Escalation Vulnerability
Android

Android Framework contains an unspecified vulnerability that allows for privilege escalation.

Refssource.android.comnvd.nist.gov
Federal remediation due 2023-10-04
CVE-2023-20269
2023-09-13
Cisco Adaptive Security Appliance and Firepower Threat Defense Unauthorized Access VulnerabilityRansomware
Cisco

Cisco Adaptive Security Appliance and Firepower Threat Defense contain an unauthorized access vulnerability that could allow an unauthenticated, remote attacker to conduct a brute force attack in an attempt to identify valid username and password combinations or establish a clientless SSL VPN session with an unauthorized user.

CWE-288 · Authentication bypass
Refssec.cloudapps.cisco.comnvd.nist.gov
Federal remediation due 2023-10-04
CVE-2023-36802
2023-09-12
Microsoft Streaming Service Proxy Privilege Escalation Vulnerability
Microsoft

Microsoft Streaming Service Proxy contains an unspecified vulnerability that allows for privilege escalation.

CWE-416 · Use after free
Refsmsrc.microsoft.comnvd.nist.gov
Federal remediation due 2023-10-03
CVE-2023-36761
2023-09-12
Microsoft Word Information Disclosure Vulnerability
Microsoft

Microsoft Word contains an unspecified vulnerability that allows for information disclosure.

CWE-668
Refsmsrc.microsoft.comnvd.nist.gov
Federal remediation due 2023-10-03
CVE-2023-41064
2023-09-11
Apple iOS, iPadOS, and macOS ImageIO Buffer Overflow Vulnerability
Apple

Apple iOS, iPadOS, and macOS contain a buffer overflow vulnerability in ImageIO when processing a maliciously crafted image, which may lead to code execution. This vulnerability was chained with CVE-2023-41061.

CWE-120 · Classic buffer overflow
Refssupport.apple.comnvd.nist.gov
Federal remediation due 2023-10-02
CVE-2023-41061
2023-09-11
Apple iOS, iPadOS, and watchOS Wallet Code Execution Vulnerability
Apple

Apple iOS, iPadOS, and watchOS contain an unspecified vulnerability due to a validation issue affecting Wallet in which a maliciously crafted attachment may result in code execution. This vulnerability was chained with CVE-2023-41064.

Refssupport.apple.comnvd.nist.gov
Federal remediation due 2023-10-02
CVE-2023-33246
2023-09-06
Apache RocketMQ Command Execution Vulnerability
Apache

Several components of Apache RocketMQ, including NameServer, Broker, and Controller, are exposed to the extranet and lack permission verification. An attacker can exploit this vulnerability by using the update configuration function to execute commands as the system users that RocketMQ is running as or achieve the same effect by forging the RocketMQ protocol content.

CWE-94 · Code injection
Refslists.apache.orgnvd.nist.gov
Federal remediation due 2023-09-27
CVE-2023-38831
2023-08-24
RARLAB WinRAR Code Execution VulnerabilityRansomware
RARLAB

RARLAB WinRAR contains an unspecified vulnerability that allows an attacker to execute code when a user attempts to view a benign file within a ZIP archive.

CWE-351
Refswin-rar.comnvd.nist.gov
Federal remediation due 2023-09-14
CVE-2023-32315
2023-08-24
Ignite Realtime Openfire Path Traversal Vulnerability
Ignite Realtime

Ignite Realtime Openfire contains a path traversal vulnerability that allows an unauthenticated attacker to access restricted pages in the Openfire Admin Console reserved for administrative users.

CWE-22 · Path traversal
Refsigniterealtime.orgnvd.nist.gov
Federal remediation due 2023-09-14
Prev14 / 34Next