Rosetta Intel
Datasets/KEV CatalogThreat ActorsAttack Surface
Rosetta Lab ↗Blur Horizon LLC
Datasets

KEV Catalog

CISA, queryable

Known exploited vulnerabilities as a queryable table — by CVE, vendor or product.

1685 entries·352 Ransomware·Updated 2026-08-27

1685 results·Page 20 / 34

CVE-2016-3393
2022-05-25
Microsoft Windows Graphics Device Interface (GDI) Remote Code Execution Vulnerability
Microsoft

A remote code execution vulnerability exists due to the way the Windows GDI component handles objects in the memory. An attacker who successfully exploits this vulnerability could take control of the affected system.

CWE-284 · Improper access control
Refsnvd.nist.gov
Federal remediation due 2022-06-15
CVE-2016-1010
2022-05-25
Adobe Flash Player and AIR Integer Overflow Vulnerability
Adobe

Integer overflow vulnerability in Adobe Flash Player and AIR allows attackers to execute code.

CWE-190 · Integer overflow
Refsnvd.nist.gov
Federal remediation due 2022-06-15
CVE-2016-0984
2022-05-25
Adobe Flash Player and AIR Use-After-Free Vulnerability
Adobe

Use-after-free vulnerability in Adobe Flash Player and Adobe AIR allows attackers to execute code.

CWE-416 · Use after free
Refsnvd.nist.gov
Federal remediation due 2022-06-15
CVE-2016-0034
2022-05-25
Microsoft Silverlight Runtime Remote Code Execution VulnerabilityRansomware
Microsoft

Microsoft Silverlight mishandles negative offsets during decoding, which allows attackers to execute remote code or cause a denial-of-service (DoS).

CWE-20 · Improper input validation
Refsnvd.nist.gov
Federal remediation due 2022-06-15
CVE-2015-8651
2022-05-25
Adobe Flash Player Integer Overflow Vulnerability
Adobe

Integer overflow in Adobe Flash Player allows attackers to execute code.

CWE-189
Refsnvd.nist.gov
Federal remediation due 2022-06-15
CVE-2015-6175
2022-05-25
Microsoft Windows Kernel Privilege Escalation Vulnerability
Microsoft

The kernel in Microsoft Windows contains a vulnerability that allows local users to gain privileges via a crafted application.

CWE-264 · Permissions and access control
Refsnvd.nist.gov
Federal remediation due 2022-06-15
CVE-2015-4495
2022-05-25
Mozilla Firefox Security Feature Bypass Vulnerability
Mozilla

Moxilla Firefox allows remote attackers to bypass the Same Origin Policy to read arbitrary files or gain privileges.

CWE-200 · Information exposure
Refsnvd.nist.gov
Federal remediation due 2022-06-15
CVE-2015-2425
2022-05-25
Microsoft Internet Explorer Memory Corruption Vulnerability
Microsoft

Microsoft Internet Explorer contains a memory corruption vulnerability that allows remote attackers to execute code or cause denial-of-service (DoS).

CWE-119 · Memory buffer bounds
Refsnvd.nist.gov
Federal remediation due 2022-06-15
CVE-2015-2360
2022-05-25
Microsoft Win32k Privilege Escalation Vulnerability
Microsoft

Win32k.sys in the kernel-mode drivers in Microsoft Windows allows local users to gain privileges or cause denial-of-service (DoS).

CWE-119 · Memory buffer bounds
Refsnvd.nist.gov
Federal remediation due 2022-06-15
CVE-2015-1769
2022-05-25
Microsoft Windows Mount Manager Privilege Escalation Vulnerability
Microsoft

A privilege escalation vulnerability exists when the Windows Mount Manager component improperly processes symbolic links.

CWE-264 · Permissions and access control
Refsnvd.nist.gov
Federal remediation due 2022-06-15
CVE-2015-1671
2022-05-25
Microsoft Windows Remote Code Execution Vulnerability
Microsoft

A remote code execution vulnerability exists when components of Windows, .NET Framework, Office, Lync, and Silverlight fail to properly handle TrueType fonts.

CWE-19
Refsnvd.nist.gov
Federal remediation due 2022-06-15
CVE-2015-0310
2022-05-25
Adobe Flash Player ASLR Bypass Vulnerability
Adobe

Adobe Flash Player does not properly restrict discovery of memory addresses, which allows attackers to bypass the address space layout randomization (ASLR) protection mechanism.

CWE-264 · Permissions and access control
Refsnvd.nist.gov
Federal remediation due 2022-06-15
CVE-2015-0071
2022-05-25
Microsoft Internet Explorer ASLR Bypass Vulnerability
Microsoft

Microsoft Internet Explorer allows remote attackers to bypass the address space layout randomization (ASLR) protection mechanism via a crafted web site.

CWE-264 · Permissions and access control
Refsnvd.nist.gov
Federal remediation due 2022-06-15
CVE-2015-0016
2022-05-25
Microsoft Windows TS WebProxy Directory Traversal Vulnerability
Microsoft

Directory traversal vulnerability in the TS WebProxy (TSWbPrxy) component in Microsoft Windows allows remote attackers to escalate privileges.

CWE-22 · Path traversal
Refsnvd.nist.gov
Federal remediation due 2022-06-15
CVE-2014-8439
2022-05-25
Adobe Flash Player Dereferenced Pointer Vulnerability
Adobe

Adobe Flash Player has a vulnerability in the way it handles a dereferenced memory pointer which could lead to code execution.

CWE-119 · Memory buffer bounds
Refsnvd.nist.gov
Federal remediation due 2022-06-15
CVE-2014-4148
2022-05-25
Microsoft Windows Remote Code Execution Vulnerability
Microsoft

A remote code execution vulnerability exists when the Windows kernel-mode driver improperly handles TrueType fonts.

CWE-94 · Code injection
Refsnvd.nist.gov
Federal remediation due 2022-06-15
CVE-2014-4123
2022-05-25
Microsoft Internet Explorer Privilege Escalation Vulnerability
Microsoft

Microsoft Internet Explorer contains an unspecified vulnerability that allows remote attackers to gain privileges via a crafted web site.

CWE-264 · Permissions and access control
Refsnvd.nist.gov
Federal remediation due 2022-06-15
CVE-2014-4077
2022-05-25
Microsoft IME Japanese Privilege Escalation Vulnerability
Microsoft / Input Method Editor (IME) Japanese

Microsoft Input Method Editor (IME) Japanese is a keyboard with Japanese characters that can be enabled on Windows systems as it is included by default (with the default set as disabled). IME Japanese contains an unspecified vulnerability when IMJPDCT.EXE (IME for Japanese) is installed which allows attackers to bypass a sandbox and perform privilege escalation.

CWE-264 · Permissions and access control
Refsnvd.nist.gov
Federal remediation due 2022-06-15
CVE-2014-3153
2022-05-25
Linux Kernel Privilege Escalation Vulnerability
Linux

The futex_requeue function in kernel/futex.c in Linux kernel does not ensure that calls have two different futex addresses, which allows local users to gain privileges.

CWE-269 · Improper privilege management
Refsnvd.nist.gov
Federal remediation due 2022-06-15
CVE-2014-2817
2022-05-25
Microsoft Internet Explorer Privilege Escalation Vulnerability
Microsoft

Microsoft Internet Explorer cotains an unspecified vulnerability that allows remote attackers to gain privileges via a crafted web site.

CWE-264 · Permissions and access control
Refsnvd.nist.gov
Federal remediation due 2022-06-15
CVE-2014-0546
2022-05-25
Adobe Reader and Acrobat Sandbox Bypass Vulnerability
Adobe

Adobe Reader and Acrobat on Windows allow attackers to bypass a sandbox protection mechanism, and consequently execute native code in a privileged context.

Refsnvd.nist.gov
Federal remediation due 2022-06-15
CVE-2013-7331
2022-05-25
Microsoft Internet Explorer Information Disclosure Vulnerability
Microsoft

An information disclosure vulnerability exists in Internet Explorer which allows resources loaded into memory to be queried. This vulnerability could allow an attacker to detect anti-malware applications.

CWE-200 · Information exposure
Refsnvd.nist.gov
Federal remediation due 2022-06-15
CVE-2013-3993
2022-05-25
IBM InfoSphere BigInsights Invalid Input VulnerabilityRansomware
IBM

Certain APIs within BigInsights can take invalid input that might allow attackers unauthorized access to read, write, modify, or delete data.

CWE-264 · Permissions and access control
Refsnvd.nist.gov
Federal remediation due 2022-06-15
CVE-2013-3896
2022-05-25
Microsoft Silverlight Information Disclosure Vulnerability
Microsoft

Microsoft Silverlight does not properly validate pointers during access to Silverlight elements, which allows remote attackers to obtain sensitive information via a crafted Silverlight application.

CWE-20 · Improper input validation
Refsnvd.nist.gov
Federal remediation due 2022-06-15
CVE-2013-2423
2022-05-25
Oracle JRE Unspecified Vulnerability
Oracle / Java Runtime Environment (JRE)

Unspecified vulnerability in hotspot for Java Runtime Environment (JRE) allows remote attackers to affect integrity.

Refsnvd.nist.gov
Federal remediation due 2022-06-15
CVE-2013-0431
2022-05-25
Oracle JRE Sandbox Bypass VulnerabilityRansomware
Oracle / Java Runtime Environment (JRE)

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle allows remote attackers to bypass the Java security sandbox.

Refsnvd.nist.gov
Federal remediation due 2022-06-15
CVE-2013-0422
2022-05-25
Oracle JRE Remote Code Execution VulnerabilityRansomware
Oracle / Java Runtime Environment (JRE)

A vulnerability in the way Java restricts the permissions of Java applets could allow an attacker to execute commands on a vulnerable system.

CWE-264 · Permissions and access control
Refsnvd.nist.gov
Federal remediation due 2022-06-15
CVE-2013-0074
2022-05-25
Microsoft Silverlight Double Dereference VulnerabilityRansomware
Microsoft

Microsoft Silverlight does not properly validate pointers during HTML object rendering, which allows remote attackers to execute code via a crafted Silverlight application.

Refsnvd.nist.gov
Federal remediation due 2022-06-15
CVE-2012-1710
2022-05-25
Oracle Fusion Middleware Unspecified VulnerabilityRansomware
Oracle

Unspecified vulnerability in the Oracle WebCenter Forms Recognition component in Oracle Fusion Middleware allows remote attackers to affect confidentiality, integrity, and availability via Unknown vectors related to Designer.

Refsnvd.nist.gov
Federal remediation due 2022-06-15
CVE-2010-1428
2022-05-25
Red Hat JBoss Information Disclosure VulnerabilityRansomware
Red Hat

Unauthenticated access to the JBoss Application Server Web Console (/web-console) is blocked by default. However, it was found that this block was incomplete, and only blocked GET and POST HTTP verbs. A remote attacker could use this flaw to gain access to sensitive information.

CWE-264 · Permissions and access control
Refsnvd.nist.gov
Federal remediation due 2022-06-15
CVE-2010-0840
2022-05-25
Oracle JRE Unspecified Vulnerability
Oracle / Java Runtime Environment (JRE)

Unspecified vulnerability in the Java Runtime Environment (JRE) in Java SE component allows remote attackers to affect confidentiality, integrity, and availability via Unknown vectors.

Refsnvd.nist.gov
Federal remediation due 2022-06-15
CVE-2010-0738
2022-05-25
Red Hat JBoss Authentication Bypass VulnerabilityRansomware
Red Hat

The JMX-Console web application in JBossAs in Red Hat JBoss Enterprise Application Platform performs access control only for the GET and POST methods, which allows remote attackers to send requests to this application's GET handler by using a different method.

CWE-264 · Permissions and access control
Refsnvd.nist.gov
Federal remediation due 2022-06-15
CVE-2018-8611
2022-05-24
Microsoft Windows Kernel Privilege Escalation Vulnerability
Microsoft

A privilege escalation vulnerability exists when the Windows kernel fails to properly handle objects in memory.

CWE-404
Refsnvd.nist.gov
Federal remediation due 2022-06-14
CVE-2018-19953
2022-05-24
QNAP NAS File Station Cross-Site Scripting VulnerabilityRansomware
QNAP / Network Attached Storage (NAS)

A cross-site scripting vulnerability affecting QNAP NAS File Station could allow remote attackers to inject malicious code.

CWE-79 · Cross-site scriptingCWE-80
Refsnvd.nist.gov
Federal remediation due 2022-06-14
CVE-2018-19949
2022-05-24
QNAP NAS File Station Command Injection VulnerabilityRansomware
QNAP / Network Attached Storage (NAS)

A command injection vulnerability affecting QNAP NAS File Station could allow remote attackers to run commands.

CWE-20 · Improper input validationCWE-77 · Command injectionCWE-78 · OS command injection
Refsnvd.nist.gov
Federal remediation due 2022-06-14
CVE-2018-19943
2022-05-24
QNAP NAS File Station Cross-Site Scripting VulnerabilityRansomware
QNAP / Network Attached Storage (NAS)

A cross-site scripting vulnerability affecting QNAP NAS File Station could allow remote attackers to inject malicious code.

CWE-79 · Cross-site scriptingCWE-80
Refsnvd.nist.gov
Federal remediation due 2022-06-14
CVE-2017-8543
2022-05-24
Microsoft Windows Search Remote Code Execution Vulnerability
Microsoft

Microsoft Windows allows an attacker to take control of the affected system when Windows Search fails to handle objects in memory.

CWE-281
Refsnvd.nist.gov
Federal remediation due 2022-06-14
CVE-2017-8291
2022-05-24
Artifex Ghostscript Type Confusion Vulnerability
Artifex

Artifex Ghostscript allows -dSAFER bypass and remote command execution via .rsdparams type confusion with a "/OutputFile.

CWE-704
Refsnvd.nist.gov
Federal remediation due 2022-06-14
CVE-2017-18362
2022-05-24
Kaseya VSA SQL Injection VulnerabilityRansomware
Kaseya / Virtual System/Server Administrator (VSA)

ConnectWise ManagedITSync integration for Kaseya VSA is vulnerable to unauthenticated remote commands that allow full direct access to the Kaseya VSA database.

CWE-89 · SQL injection
Refsnvd.nist.gov
Federal remediation due 2022-06-14
CVE-2017-0210
2022-05-24
Microsoft Internet Explorer Privilege Escalation Vulnerability
Microsoft

A privilege escalation vulnerability exists when Internet Explorer does not properly enforce cross-domain policies, which could allow an attacker to access information.

Refsnvd.nist.gov
Federal remediation due 2022-06-14
CVE-2017-0149
2022-05-24
Microsoft Internet Explorer Memory Corruption Vulnerability
Microsoft

Microsoft Internet Explorer contains a memory corruption vulnerability that allows remote attackers to execute code or cause a denial-of-service (DoS) via a crafted website.

CWE-119 · Memory buffer bounds
Refsnvd.nist.gov
Federal remediation due 2022-06-14
CVE-2017-0147
2022-05-24
Microsoft Windows SMBv1 Information Disclosure VulnerabilityRansomware
Microsoft / SMBv1 server

The SMBv1 server in Microsoft Windows allows remote attackers to obtain sensitive information from process memory via a crafted packet.

CWE-200 · Information exposure
Refsnvd.nist.gov
Federal remediation due 2022-06-14
CVE-2017-0022
2022-05-24
Microsoft XML Core Services Information Disclosure Vulnerability
Microsoft

Microsoft XML Core Services (MSXML) improperly handles objects in memory, allowing attackers to test for files on disk via a crafted web site.

CWE-200 · Information exposure
Refsnvd.nist.gov
Federal remediation due 2022-06-14
CVE-2017-0005
2022-05-24
Microsoft Windows Graphics Device Interface (GDI) Privilege Escalation Vulnerability
Microsoft

The Graphics Device Interface (GDI) in Microsoft Windows allows local users to gain privileges via a crafted application.

CWE-119 · Memory buffer bounds
Refsnvd.nist.gov
Federal remediation due 2022-06-14
CVE-2016-6367
2022-05-24
Cisco Adaptive Security Appliance (ASA) CLI Remote Code Execution Vulnerability
Cisco

A vulnerability in the command-line interface (CLI) parser of Cisco ASA software could allow an authenticated, local attacker to create a denial-of-service (DoS) condition or potentially execute code.

CWE-77 · Command injection
Refsnvd.nist.gov
Federal remediation due 2022-06-14
CVE-2016-6366
2022-05-24
Cisco Adaptive Security Appliance (ASA) SNMP Buffer Overflow Vulnerability
Cisco

A buffer overflow vulnerability in the Simple Network Management Protocol (SNMP) code of Cisco ASA software could allow an attacker to cause a reload of the affected system or to remotely execute code.

CWE-119 · Memory buffer bounds
Refsnvd.nist.gov
Federal remediation due 2022-06-14
CVE-2016-4657
2022-05-24
Apple iOS Webkit Memory Corruption Vulnerability
Apple

Apple iOS WebKit contains a memory corruption vulnerability that allows attackers to execute remote code or cause a denial-of-service (DoS) via a crafted web site. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing.

CWE-119 · Memory buffer bounds
Refsnvd.nist.gov
Federal remediation due 2022-06-14
CVE-2016-4656
2022-05-24
Apple iOS Memory Corruption Vulnerability
Apple

A memory corruption vulnerability in Apple iOS kernel allows attackers to execute code in a privileged context or cause a denial-of-service (DoS) via a crafted application.

CWE-264 · Permissions and access control
Refsnvd.nist.gov
Federal remediation due 2022-06-14
CVE-2016-4655
2022-05-24
Apple iOS Information Disclosure Vulnerability
Apple

The Apple iOS kernel allows attackers to obtain sensitive information from memory via a crafted application.

CWE-200 · Information exposure
Refsnvd.nist.gov
Federal remediation due 2022-06-14
CVE-2016-3351
2022-05-24
Microsoft Internet Explorer and Edge Information Disclosure VulnerabilityRansomware
Microsoft

An information disclosure vulnerability exists in the way that certain functions in Internet Explorer and Edge handle objects in memory. The vulnerability could allow an attacker to detect specific files on the user's computer.

CWE-200 · Information exposure
Refsnvd.nist.gov
Federal remediation due 2022-06-14
Prev20 / 34Next