Rosetta Intel
Datasets/KEV CatalogThreat ActorsAttack Surface
Rosetta Lab ↗Blur Horizon LLC
Datasets

KEV Catalog

CISA, queryable

Known exploited vulnerabilities as a queryable table — by CVE, vendor or product.

1685 entries·352 Ransomware·Updated 2026-08-27

1685 results·Page 19 / 34

CVE-2022-29499
2022-06-27
Mitel MiVoice Connect Data Validation VulnerabilityRansomware
Mitel

The Service Appliance component in Mitel MiVoice Connect allows remote code execution due to incorrect data validation.

CWE-20 · Improper input validation
Refsnvd.nist.gov
Federal remediation due 2022-07-18
CVE-2021-4034
2022-06-27
Red Hat Polkit Out-of-Bounds Read and Write VulnerabilityRansomware
Red Hat

The Red Hat polkit pkexec utility contains an out-of-bounds read and write vulnerability that allows for privilege escalation with administrative rights.

CWE-787 · Out-of-bounds write
Refsnvd.nist.gov
Federal remediation due 2022-07-18
CVE-2021-30983
2022-06-27
Apple iOS and iPadOS Buffer Overflow Vulnerability
Apple

Apple iOS and iPadOS contain a buffer overflow vulnerability that could allow an application to execute code with kernel privileges.

CWE-119 · Memory buffer bounds
Refsnvd.nist.gov
Federal remediation due 2022-07-18
CVE-2021-30533
2022-06-27
Google Chromium PopupBlocker Security Bypass Vulnerability
Google

Google Chromium PopupBlocker contains an insufficient policy enforcement vulnerability that allows a remote attacker to bypass navigation restrictions via a crafted iframe. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

CWE-863
Refsnvd.nist.gov
Federal remediation due 2022-07-18
CVE-2020-9907
2022-06-27
Apple Multiple Products Memory Corruption Vulnerability
Apple

Apple iOS, iPadOS, and tvOS contain a memory corruption vulnerability that could allow an application to execute code with kernel privileges.

CWE-787 · Out-of-bounds write
Refsnvd.nist.gov
Federal remediation due 2022-07-18
CVE-2020-3837
2022-06-27
Apple Multiple Products Memory Corruption Vulnerability
Apple

Apple iOS, iPadOS, macOS, tvOS, and watchOS contain a memory corruption vulnerability that could allow an application to execute code with kernel privileges.

CWE-787 · Out-of-bounds write
Refsnvd.nist.gov
Federal remediation due 2022-07-18
CVE-2019-8605
2022-06-27
Apple Multiple Products Use-After-Free Vulnerability
Apple

A use-after-free vulnerability in Apple iOS, macOS, tvOS, and watchOS could allow a malicious application to execute code with system privileges.

CWE-416 · Use after free
Refsnvd.nist.gov
Federal remediation due 2022-07-18
CVE-2018-4344
2022-06-27
Apple Multiple Products Memory Corruption Vulnerability
Apple

Apple iOS, macOS, tvOS, and watchOS contain a memory corruption vulnerability which can allow for code execution.

CWE-119 · Memory buffer bounds
Refsnvd.nist.gov
Federal remediation due 2022-07-18
CVE-2022-30190
2022-06-14
Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution VulnerabilityRansomware
Microsoft

A remote code execution vulnerability exists when MSDT is called using the URL protocol from a calling application such as Word. An attacker who successfully exploits this vulnerability can run code with the privileges of the calling application.

CWE-610
Refsnvd.nist.gov
Federal remediation due 2022-07-05
CVE-2021-38163
2022-06-09
SAP NetWeaver Unrestricted File Upload Vulnerability
SAP

SAP NetWeaver contains a vulnerability that allows unrestricted file upload.

CWE-23 · Relative path traversal
Refsnvd.nist.gov
Federal remediation due 2022-06-30
CVE-2016-2388
2022-06-09
SAP NetWeaver Information Disclosure Vulnerability
SAP

The Universal Worklist Configuration in SAP NetWeaver AS JAVA 7.4 allows remote attackers to obtain sensitive user information via a crafted HTTP request.

CWE-200 · Information exposure
Refsnvd.nist.gov
Federal remediation due 2022-06-30
CVE-2016-2386
2022-06-09
SAP NetWeaver SQL Injection Vulnerability
SAP

SQL injection vulnerability in the UDDI server in SAP NetWeaver J2EE Engine 7.40 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

CWE-89 · SQL injection
Refsnvd.nist.gov
Federal remediation due 2022-06-30
CVE-2019-7195
2022-06-08
QNAP Photo Station Path Traversal VulnerabilityRansomware
QNAP

QNAP devices running Photo Station contain an external control of file name or path vulnerability allowing remote attackers to access or modify system files.

CWE-22 · Path traversal
Refsnvd.nist.gov
Federal remediation due 2022-06-22
CVE-2019-7194
2022-06-08
QNAP Photo Station Path Traversal VulnerabilityRansomware
QNAP

QNAP devices running Photo Station contain an external control of file name or path vulnerability allowing remote attackers to access or modify system files.

CWE-22 · Path traversal
Refsnvd.nist.gov
Federal remediation due 2022-06-22
CVE-2019-7193
2022-06-08
QNAP QTS Improper Input Validation VulnerabilityRansomware
QNAP

QNAP QTS contains an improper input validation vulnerability allowing remote attackers to inject code on the system.

CWE-20 · Improper input validation
Refsnvd.nist.gov
Federal remediation due 2022-06-22
CVE-2019-7192
2022-06-08
QNAP Photo Station Improper Access Control VulnerabilityRansomware
QNAP

QNAP NAS devices running Photo Station contain an improper access control vulnerability allowing remote attackers to gain unauthorized access to the system.

CWE-863
Refsnvd.nist.gov
Federal remediation due 2022-06-22
CVE-2019-5825
2022-06-08
Google Chromium V8 Out-of-Bounds Write Vulnerability
Google

Google Chromium V8 Engine contains an out-of-bounds write vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

CWE-787 · Out-of-bounds write
Refsnvd.nist.gov
Federal remediation due 2022-06-22
CVE-2019-15271
2022-06-08
Cisco RV Series Routers Deserialization of Untrusted Data Vulnerability
Cisco

A deserialization of untrusted data vulnerability in the web-based management interface of certain Cisco Small Business RV Series Routers could allow an attacker to execute code with root privileges.

CWE-502 · Deserialization of untrusted data
Refsnvd.nist.gov
Federal remediation due 2022-06-22
CVE-2018-6065
2022-06-08
Google Chromium V8 Integer Overflow Vulnerability
Google

Google Chromium V8 Engine contains an integer overflow vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

CWE-190 · Integer overflowCWE-787 · Out-of-bounds write
Refsnvd.nist.gov
Federal remediation due 2022-06-22
CVE-2018-4990
2022-06-08
Adobe Acrobat and Reader Double Free Vulnerability
Adobe

Adobe Acrobat and Reader have a double free vulnerability that could lead to remote code execution.

CWE-415
Refsnvd.nist.gov
Federal remediation due 2022-06-22
CVE-2018-17480
2022-06-08
Google Chromium V8 Out-of-Bounds Write Vulnerability
Google

Google Chromium V8 Engine contains out-of-bounds write vulnerability that allows a remote attacker to execute code inside a sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

CWE-787 · Out-of-bounds write
Refsnvd.nist.gov
Federal remediation due 2022-06-22
CVE-2018-17463
2022-06-08
Google Chromium V8 Remote Code Execution Vulnerability
Google

Google Chromium V8 Engine contains an unspecified vulnerability that allows a remote attacker to execute code inside a sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

Refsnvd.nist.gov
Federal remediation due 2022-06-22
CVE-2017-6862
2022-06-08
NETGEAR Multiple Devices Buffer Overflow Vulnerability
NETGEAR

Multiple NETGEAR devices contain a buffer overflow vulnerability that allows for authentication bypass and remote code execution.

CWE-119 · Memory buffer bounds
Refsnvd.nist.gov
Federal remediation due 2022-06-22
CVE-2017-5070
2022-06-08
Google Chromium V8 Type Confusion Vulnerability
Google

Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to execute code inside a sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

CWE-843 · Type confusion
Refsnvd.nist.gov
Federal remediation due 2022-06-22
CVE-2017-5030
2022-06-08
Google Chromium V8 Memory Corruption Vulnerability
Google

Google Chromium V8 Engine contains a memory corruption vulnerability that allows a remote attacker to execute code via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

CWE-125 · Out-of-bounds read
Refsnvd.nist.gov
Federal remediation due 2022-06-22
CVE-2016-5198
2022-06-08
Google Chromium V8 Out-of-Bounds Memory Vulnerability
Google

Google Chromium V8 Engine contains an out-of-bounds memory access vulnerability that allows a remote attacker to perform read/write operations, leading to code execution, via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

CWE-125 · Out-of-bounds readCWE-787 · Out-of-bounds write
Refsnvd.nist.gov
Federal remediation due 2022-06-22
CVE-2016-1646
2022-06-08
Google Chromium V8 Out-of-Bounds Read Vulnerability
Google

Google Chromium V8 Engine contains an out-of-bounds read vulnerability that allows a remote attacker to cause a denial of service or possibly have another unspecified impact via crafted JavaScript code. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

CWE-119 · Memory buffer bounds
Refsnvd.nist.gov
Federal remediation due 2022-06-22
CVE-2013-1331
2022-06-08
Microsoft Office Buffer Overflow Vulnerability
Microsoft

Microsoft Office contains a buffer overflow vulnerability that allows remote attackers to execute code via crafted PNG data in an Office document.

CWE-119 · Memory buffer bounds
Refsnvd.nist.gov
Federal remediation due 2022-06-22
CVE-2012-5054
2022-06-08
Adobe Flash Player Integer Overflow Vulnerability
Adobe

Adobe Flash Player contains an integer overflow vulnerability that allows remote attackers to execute code via malformed arguments.

CWE-189
Refsnvd.nist.gov
Federal remediation due 2022-06-22
CVE-2012-4969
2022-06-08
Microsoft Internet Explorer Use-After-Free Vulnerability
Microsoft

Microsoft Internet Explorer contains a use-after-free vulnerability that allows remote attackers to execute code via a crafted web site.

Refsnvd.nist.gov
Federal remediation due 2022-06-22
CVE-2012-1889
2022-06-08
Microsoft XML Core Services Memory Corruption Vulnerability
Microsoft

Microsoft XML Core Services contains a memory corruption vulnerability which could allow for remote code execution.

CWE-119 · Memory buffer bounds
Refsnvd.nist.gov
Federal remediation due 2022-06-22
CVE-2012-0767
2022-06-08
Adobe Flash Player Cross-Site Scripting (XSS) Vulnerability
Adobe

Adobe Flash Player contains a XSS vulnerability that allows remote attackers to inject web script or HTML.

CWE-79 · Cross-site scripting
Refsnvd.nist.gov
Federal remediation due 2022-06-22
CVE-2012-0754
2022-06-08
Adobe Flash Player Memory Corruption Vulnerability
Adobe

Adobe Flash Player contains a memory corruption vulnerability that allows remote attackers to execute code or cause denial-of-service (DoS).

CWE-787 · Out-of-bounds write
Refsnvd.nist.gov
Federal remediation due 2022-06-22
CVE-2012-0151
2022-06-08
Microsoft Windows Authenticode Signature Verification Remote Code Execution Vulnerability
Microsoft

The Authenticode Signature Verification function in Microsoft Windows (WinVerifyTrust) does not properly validate the digest of a signed portable executable (PE) file, which allows user-assisted remote attackers to execute code.

CWE-20 · Improper input validation
Refsnvd.nist.gov
Federal remediation due 2022-06-22
CVE-2011-2462
2022-06-08
Adobe Reader and Acrobat Universal 3D Memory Corruption Vulnerability
Adobe

The Universal 3D (U3D) component in Adobe Reader and Acrobat contains a memory corruption vulnerability which could allow remote attackers to execute code or cause denial-of-service (DoS).

CWE-787 · Out-of-bounds write
Refsnvd.nist.gov
Federal remediation due 2022-06-22
CVE-2011-0609
2022-06-08
Adobe Flash Player Unspecified Vulnerability
Adobe

Adobe Flash Player contains an unspecified vulnerability that allows remote attackers to execute code or cause denial-of-service (DoS).

Refsnvd.nist.gov
Federal remediation due 2022-06-22
CVE-2010-2883
2022-06-08
Adobe Acrobat and Reader Stack-Based Buffer Overflow Vulnerability
Adobe

Adobe Acrobat and Reader contain a stack-based buffer overflow vulnerability that allows remote attackers to execute code or cause denial-of-service (DoS).

CWE-119 · Memory buffer bounds
Refsnvd.nist.gov
Federal remediation due 2022-06-22
CVE-2010-2572
2022-06-08
Microsoft PowerPoint Buffer Overflow Vulnerability
Microsoft

Microsoft PowerPoint contains a buffer overflow vulnerability that alllows for remote code execution.

CWE-119 · Memory buffer bounds
Refsnvd.nist.gov
Federal remediation due 2022-06-22
CVE-2010-1297
2022-06-08
Adobe Flash Player Memory Corruption Vulnerability
Adobe

Adobe Flash Player contains a memory corruption vulnerability that allows remote attackers to execute code or cause denial-of-service (DoS).

CWE-787 · Out-of-bounds write
Refsnvd.nist.gov
Federal remediation due 2022-06-22
CVE-2009-4324
2022-06-08
Adobe Acrobat and Reader Use-After-Free Vulnerability
Adobe

Use-after-free vulnerability in Adobe Acrobat and Reader allows remote attackers to execute code via a crafted PDF file.

CWE-399 · Resource management
Refsnvd.nist.gov
Federal remediation due 2022-06-22
CVE-2009-3953
2022-06-08
Adobe Acrobat and Reader Universal 3D Remote Code Execution Vulnerability
Adobe

Adobe Acrobat and Reader contains an array boundary issue in Universal 3D (U3D) support that could lead to remote code execution.

CWE-119 · Memory buffer bounds
Refsnvd.nist.gov
Federal remediation due 2022-06-22
CVE-2009-1862
2022-06-08
Adobe Acrobat and Reader, Flash Player Unspecified Vulnerability
Adobe

Adobe Acrobat and Reader and Adobe Flash Player allows remote attackers to execute code or cause denial-of-service (DoS).

CWE-94 · Code injection
Refsnvd.nist.gov
Federal remediation due 2022-06-22
CVE-2009-0563
2022-06-08
Microsoft Office Buffer Overflow Vulnerability
Microsoft

Microsoft Office contains a buffer overflow vulnerability that allows remote attackers to execute code via a Word document with a crafted tag containing an invalid length field.

CWE-119 · Memory buffer bounds
Refsnvd.nist.gov
Federal remediation due 2022-06-22
CVE-2009-0557
2022-06-08
Microsoft Office Object Record Corruption Vulnerability
Microsoft

Microsoft Office contains an object record corruption vulnerability that allows remote attackers to execute code via a crafted Excel file with a malformed record object.

CWE-94 · Code injection
Refsnvd.nist.gov
Federal remediation due 2022-06-22
CVE-2008-0655
2022-06-08
Adobe Acrobat and Reader Unspecified Vulnerability
Adobe

Adobe Acrobat and Reader contains an unespecified vulnerability described as a design flaw which could allow a specially crafted file to be printed silently an arbitrary number of times.

Refsnvd.nist.gov
Federal remediation due 2022-06-22
CVE-2007-5659
2022-06-08
Adobe Acrobat and Reader Buffer Overflow Vulnerability
Adobe

Adobe Acrobat and Reader contain a buffer overflow vulnerability that allows remote attackers to execute code via a PDF file with long arguments to unspecified JavaScript methods.

CWE-119 · Memory buffer bounds
Refsnvd.nist.gov
Federal remediation due 2022-06-22
CVE-2006-2492
2022-06-08
Microsoft Word Malformed Object Pointer Vulnerability
Microsoft

Microsoft Word and Microsoft Works Suites contain a malformed object pointer which allows attackers to execute code.

CWE-120 · Classic buffer overflow
Refsnvd.nist.gov
Federal remediation due 2022-06-22
CVE-2022-26134
2022-06-02
Atlassian Confluence Server and Data Center Remote Code Execution VulnerabilityRansomware
Atlassian / Confluence Server/Data Center

Atlassian Confluence Server and Data Center contain a remote code execution vulnerability that allows for an unauthenticated attacker to perform remote code execution.

CWE-917
Refsnvd.nist.gov
Federal remediation due 2022-06-06
CVE-2019-3010
2022-05-25
Oracle Solaris Privilege Escalation Vulnerability
Oracle

Oracle Solaris component: XScreenSaver contains an unspecified vulnerability that allows for privilege escalation.

Refsnvd.nist.gov
Federal remediation due 2022-06-15
CVE-2016-7256
2022-05-25
Microsoft Windows Open Type Font Remote Code Execution Vulnerability
Microsoft

A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts. An attacker who successfully exploits this vulnerability could take control of the affected system.

CWE-284 · Improper access control
Refsnvd.nist.gov
Federal remediation due 2022-06-15
Prev19 / 34Next