Rosetta Intel
Datasets/KEV CatalogThreat ActorsAttack Surface
Rosetta Lab ↗Blur Horizon LLC
Datasets

KEV Catalog

CISA, queryable

Known exploited vulnerabilities as a queryable table — by CVE, vendor or product.

1685 entries·352 Ransomware·Updated 2026-08-27

1685 results·Page 22 / 34

CVE-2022-22954
2022-04-14
VMware Workspace ONE Access and Identity Manager Server-Side Template Injection VulnerabilityRansomware
VMware

VMware Workspace ONE Access and Identity Manager allow for remote code execution due to server-side template injection.

CWE-94 · Code injection
Refsnvd.nist.gov
Federal remediation due 2022-05-05
CVE-2022-24521
2022-04-13
Microsoft Windows CLFS Driver Privilege Escalation VulnerabilityRansomware
Microsoft

Microsoft Windows Common Log File System (CLFS) Driver contains an unspecified vulnerability that allows for privilege escalation.

CWE-787 · Out-of-bounds writeCWE-1285
Refsnvd.nist.gov
Federal remediation due 2022-05-04
CVE-2018-7602
2022-04-13
Drupal Core Remote Code Execution VulnerabilityRansomware
Drupal

A remote code execution vulnerability exists within multiple subsystems of Drupal that can allow attackers to exploit multiple attack vectors on a Drupal site.

Refsnvd.nist.gov
Federal remediation due 2022-05-04
CVE-2018-20753
2022-04-13
Kaseya VSA Remote Code Execution VulnerabilityRansomware
Kaseya / Virtual System/Server Administrator (VSA)

Kaseya VSA RMM allows unprivileged remote attackers to execute PowerShell payloads on all managed devices.

Refsnvd.nist.gov
Federal remediation due 2022-05-04
CVE-2015-5123
2022-04-13
Adobe Flash Player Use-After-Free Vulnerability
Adobe

Use-after-free vulnerability in the BitmapData class in the ActionScript 3 (AS3) implementation in Adobe Flash Player allows remote attackers to execute code or cause a denial-of-service (DoS).

CWE-416 · Use after free
Refsnvd.nist.gov
Federal remediation due 2022-05-04
CVE-2015-5122
2022-04-13
Adobe Flash Player Use-After-Free Vulnerability
Adobe

Use-after-free vulnerability in the DisplayObject class in the ActionScript 3 (AS3) implementation in Adobe Flash Player allows remote attackers to execute code or cause a denial-of-service (DoS).

CWE-416 · Use after free
Refsnvd.nist.gov
Federal remediation due 2022-05-04
CVE-2015-3113
2022-04-13
Adobe Flash Player Heap-Based Buffer Overflow Vulnerability
Adobe

Heap-based buffer overflow vulnerability in Adobe Flash Player allows remote attackers to execute code.

CWE-119 · Memory buffer bounds
Refsnvd.nist.gov
Federal remediation due 2022-05-04
CVE-2015-2502
2022-04-13
Microsoft Internet Explorer Memory Corruption Vulnerability
Microsoft

Microsoft Internet Explorer contains a memory corruption vulnerability that allows an attacker to execute code or cause a denial-of-service (DoS).

CWE-119 · Memory buffer bounds
Refsnvd.nist.gov
Federal remediation due 2022-05-04
CVE-2015-0313
2022-04-13
Adobe Flash Player Use-After-Free Vulnerability
Adobe

Use-after-free vulnerability in Adobe Flash Player allows remote attackers to execute code.

CWE-416 · Use after free
Refsnvd.nist.gov
Federal remediation due 2022-05-04
CVE-2015-0311
2022-04-13
Adobe Flash Player Remote Code Execution Vulnerability
Adobe

Unspecified vulnerability in Adobe Flash Player allows remote attackers to execute code.

Refsnvd.nist.gov
Federal remediation due 2022-05-04
CVE-2014-9163
2022-04-13
Adobe Flash Player Stack-Based Buffer Overflow Vulnerability
Adobe

Stack-based buffer overflow in Adobe Flash Player allows attackers to execute code remotely.

Refsnvd.nist.gov
Federal remediation due 2022-05-04
CVE-2022-23176
2022-04-11
WatchGuard Firebox and XTM Privilege Escalation Vulnerability
WatchGuard

WatchGuard Firebox and XTM appliances allow a remote attacker with unprivileged credentials to access the system with a privileged management session via exposed management access.

Refsnvd.nist.gov
Federal remediation due 2022-05-02
CVE-2021-42287
2022-04-11
Microsoft Active Directory Domain Services Privilege Escalation VulnerabilityRansomware
Microsoft

Microsoft Active Directory Domain Services contains an unspecified vulnerability that allows for privilege escalation.

CWE-269 · Improper privilege management
Refsnvd.nist.gov
Federal remediation due 2022-05-02
CVE-2021-42278
2022-04-11
Microsoft Active Directory Domain Services Privilege Escalation VulnerabilityRansomware
Microsoft

Microsoft Active Directory Domain Services contains an unspecified vulnerability that allows for privilege escalation.

CWE-20 · Improper input validation
Refsnvd.nist.gov
Federal remediation due 2022-05-02
CVE-2021-39793
2022-04-11
Google Pixel Out-of-Bounds Write Vulnerability
Google

Google Pixel contains a possible out-of-bounds write due to a logic error in the code that could lead to local escalation of privilege.

CWE-787 · Out-of-bounds write
Refsnvd.nist.gov
Federal remediation due 2022-05-02
CVE-2021-27852
2022-04-11
Checkbox Survey Deserialization of Untrusted Data Vulnerability
Checkbox

Deserialization of Untrusted Data vulnerability in CheckboxWeb.dll of Checkbox Survey allows an unauthenticated remote attacker to execute arbitrary code.

CWE-502 · Deserialization of untrusted data
Refsnvd.nist.gov
Federal remediation due 2022-05-02
CVE-2021-22600
2022-04-11
Linux Kernel Privilege Escalation Vulnerability
Linux

Linux Kernel contains a flaw in the packet socket (AF_PACKET) implementation which could lead to incorrectly freeing memory. A local user could exploit this for denial-of-service (DoS) or possibly for privilege escalation.

CWE-415
Refsnvd.nist.gov
Federal remediation due 2022-05-02
CVE-2020-2509
2022-04-11
QNAP Network-Attached Storage (NAS) Command Injection Vulnerability
QNAP

QNAP NAS devices contain a command injection vulnerability which could allow attackers to perform remote code execution.

CWE-77 · Command injectionCWE-78 · OS command injection
Refsnvd.nist.gov
Federal remediation due 2022-05-02
CVE-2017-11317
2022-04-11
Telerik UI for ASP.NET AJAX Unrestricted File Upload Vulnerability
Telerik / User Interface (UI) for ASP.NET AJAX

Telerik.Web.UI in Progress Telerik UI for ASP.NET AJAX allows remote attackers to perform arbitrary file uploads or execute arbitrary code.

CWE-326
Refsnvd.nist.gov
Federal remediation due 2022-05-02
CVE-2021-3156
2022-04-06
Sudo Heap-Based Buffer Overflow Vulnerability
Sudo

Sudo contains an off-by-one error that can result in a heap-based buffer overflow, which allows for privilege escalation.

CWE-122 · Heap buffer overflowCWE-193
Refsnvd.nist.gov
Federal remediation due 2022-04-27
CVE-2021-31166
2022-04-06
Microsoft HTTP Protocol Stack Remote Code Execution Vulnerability
Microsoft

Microsoft HTTP Protocol Stack contains a vulnerability in http.sys that allows for remote code execution.

CWE-416 · Use after free
Refsnvd.nist.gov
Federal remediation due 2022-04-27
CVE-2017-0148
2022-04-06
Microsoft SMBv1 Server Remote Code Execution VulnerabilityRansomware
Microsoft

The SMBv1 server in Microsoft allows remote attackers to execute arbitrary code via crafted packets.

CWE-20 · Improper input validation
Refsnvd.nist.gov
Federal remediation due 2022-04-27
CVE-2022-22965
2022-04-04
Spring Framework JDK 9+ Remote Code Execution Vulnerability
VMware

Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding.

CWE-94 · Code injection
Refsnvd.nist.gov
Federal remediation due 2022-04-25
CVE-2022-22675
2022-04-04
Apple macOS Out-of-Bounds Write Vulnerability
Apple

macOS Monterey contains an out-of-bounds write vulnerability that could allow an application to execute arbitrary code with kernel privileges.

CWE-20 · Improper input validationCWE-125 · Out-of-bounds read
Refsnvd.nist.gov
Federal remediation due 2022-04-25
CVE-2022-22674
2022-04-04
Apple macOS Out-of-Bounds Read Vulnerability
Apple

macOS Monterey contains an out-of-bounds read vulnerability that could allow an application to read kernel memory.

CWE-20 · Improper input validationCWE-125 · Out-of-bounds read
Refsnvd.nist.gov
Federal remediation due 2022-04-25
CVE-2021-45382
2022-04-04
D-Link Multiple Routers Remote Code Execution Vulnerability
D-Link

A remote code execution vulnerability exists in all series H/W revisions routers via the DDNS function in ncc2 binary file.

CWE-78 · OS command injection
Refsnvd.nist.gov
Federal remediation due 2022-04-25
CVE-2022-26871
2022-03-31
Trend Micro Apex Central Arbitrary File Upload Vulnerability
Trend Micro

An arbitrary file upload vulnerability in Trend Micro Apex Central could allow for remote code execution.

CWE-184
Refsnvd.nist.gov
Federal remediation due 2022-04-21
CVE-2022-1040
2022-03-31
Sophos Firewall Authentication Bypass Vulnerability
Sophos

An authentication bypass vulnerability in User Portal and Webadmin of Sophos Firewall allows for remote code execution.

CWE-158
Refsnvd.nist.gov
Federal remediation due 2022-04-21
CVE-2021-34484
2022-03-31
Microsoft Windows User Profile Service Privilege Escalation Vulnerability
Microsoft

Microsoft Windows User Profile Service contains an unspecified vulnerability that allows for privilege escalation.

CWE-269 · Improper privilege management
Refsnvd.nist.gov
Federal remediation due 2022-04-21
CVE-2021-28799
2022-03-31
QNAP NAS Improper Authorization VulnerabilityRansomware
QNAP / Network Attached Storage (NAS)

QNAP NAS running HBS 3 contains an improper authorization vulnerability which can allow remote attackers to log in to a device.

CWE-285
Refsnvd.nist.gov
Federal remediation due 2022-04-21
CVE-2021-21551
2022-03-31
Dell dbutil Driver Insufficient Access Control Vulnerability
Dell

Dell dbutil driver contains an insufficient access control vulnerability which may lead to escalation of privileges, denial-of-service (DoS), or information disclosure.

CWE-782
Refsnvd.nist.gov
Federal remediation due 2022-04-21
CVE-2018-10562
2022-03-31
Dasan GPON Routers Command Injection VulnerabilityRansomware
Dasan / Gigabit Passive Optical Network (GPON) Routers

Dasan GPON Routers contain an authentication bypass vulnerability. When combined with CVE-2018-10561, exploitation can allow an attacker to perform remote code execution.

CWE-78 · OS command injection
Refsnvd.nist.gov
Federal remediation due 2022-04-21
CVE-2018-10561
2022-03-31
Dasan GPON Routers Authentication Bypass Vulnerability
Dasan / Gigabit Passive Optical Network (GPON) Routers

Dasan GPON Routers contain an authentication bypass vulnerability. When combined with CVE-2018-10562, exploitation can allow an attacker to perform remote code execution.

CWE-287 · Improper authentication
Refsnvd.nist.gov
Federal remediation due 2022-04-21
CVE-2022-1096
2022-03-28
Google Chromium V8 Type Confusion Vulnerability
Google

Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

CWE-843 · Type confusion
Refsnvd.nist.gov
Federal remediation due 2022-04-18
CVE-2022-0543
2022-03-28
Debian-specific Redis Server Lua Sandbox Escape Vulnerability
Redis / Debian-specific Redis Servers

Redis is prone to a (Debian-specific) Lua sandbox escape, which could result in remote code execution.

CWE-862 · Missing authorization
Refsnvd.nist.gov
Federal remediation due 2022-04-18
CVE-2021-38646
2022-03-28
Microsoft Office Access Connectivity Engine Remote Code Execution VulnerabilityRansomware
Microsoft

Microsoft Office Access Connectivity Engine contains an unspecified vulnerability which can allow for remote code execution.

Refsnvd.nist.gov
Federal remediation due 2022-04-18
CVE-2021-34486
2022-03-28
Microsoft Windows Event Tracing Privilege Escalation Vulnerability
Microsoft

Microsoft Windows Event Tracing contains an unspecified vulnerability which can allow for privilege escalation.

CWE-416 · Use after free
Refsnvd.nist.gov
Federal remediation due 2022-04-18
CVE-2021-26085
2022-03-28
Atlassian Confluence Server Pre-Authorization Arbitrary File Read VulnerabilityRansomware
Atlassian

Affected versions of Atlassian Confluence Server allow remote attackers to view restricted resources via a pre-authorization arbitrary file read vulnerability in the /s/ endpoint.

CWE-425
Refsnvd.nist.gov
Federal remediation due 2022-04-18
CVE-2021-20028
2022-03-28
SonicWall Secure Remote Access (SRA) SQL Injection VulnerabilityRansomware
SonicWall

SonicWall Secure Remote Access (SRA) products contain an improper neutralization of a SQL Command leading to SQL injection.

CWE-89 · SQL injection
Refsnvd.nist.gov
Federal remediation due 2022-04-18
CVE-2019-7483
2022-03-28
SonicWall SMA100 Directory Traversal Vulnerability
SonicWall

In SonicWall SMA100, an unauthenticated Directory Traversal vulnerability in the handleWAFRedirect CGI allows the user to test for the presence of a file on the server.

CWE-22 · Path traversal
Refsnvd.nist.gov
Federal remediation due 2022-04-18
CVE-2018-8440
2022-03-28
Microsoft Windows Privilege Escalation VulnerabilityRansomware
Microsoft

An elevation of privilege vulnerability exists when Windows improperly handles calls to Advanced Local Procedure Call (ALPC).

Refsnvd.nist.gov
Federal remediation due 2022-04-18
CVE-2018-8406
2022-03-28
Microsoft DirectX Graphics Kernel Privilege Escalation VulnerabilityRansomware
Microsoft / DirectX Graphics Kernel (DXGKRNL)

An elevation of privilege vulnerability exists when the DirectX Graphics Kernel (DXGKRNL) driver improperly handles objects in memory.

CWE-404
Refsnvd.nist.gov
Federal remediation due 2022-04-18
CVE-2018-8405
2022-03-28
Microsoft DirectX Graphics Kernel Privilege Escalation VulnerabilityRansomware
Microsoft / DirectX Graphics Kernel (DXGKRNL)

An elevation of privilege vulnerability exists when the DirectX Graphics Kernel (DXGKRNL) driver improperly handles objects in memory.

CWE-404
Refsnvd.nist.gov
Federal remediation due 2022-04-18
CVE-2017-0213
2022-03-28
Microsoft Windows Privilege Escalation VulnerabilityRansomware
Microsoft

Microsoft Windows COM Aggregate Marshaler allows for privilege escalation when an attacker runs a specially crafted application.

Refsnvd.nist.gov
Federal remediation due 2022-04-18
CVE-2017-0059
2022-03-28
Microsoft Internet Explorer Information Disclosure Vulnerability
Microsoft

Microsoft Internet Explorer allow remote attackers to obtain sensitive information from process memory via a crafted web site.

CWE-200 · Information exposure
Refsnvd.nist.gov
Federal remediation due 2022-04-18
CVE-2017-0037
2022-03-28
Microsoft Edge and Internet Explorer Type Confusion Vulnerability
Microsoft

Microsoft Edge and Internet Explorer have a type confusion vulnerability in mshtml.dll, which allows remote code execution.

CWE-704
Refsnvd.nist.gov
Federal remediation due 2022-04-18
CVE-2016-7201
2022-03-28
Microsoft Edge Memory Corruption Vulnerability
Microsoft

The Chakra JavaScript scripting engine in Microsoft Edge allows remote attackers to execute remote code or cause a denial of service (memory corruption) via a crafted web site.

CWE-119 · Memory buffer bounds
Refsnvd.nist.gov
Federal remediation due 2022-04-18
CVE-2016-7200
2022-03-28
Microsoft Edge Memory Corruption Vulnerability
Microsoft

The Chakra JavaScript scripting engine in Microsoft Edge allows remote attackers to execute remote code or cause a denial of service (memory corruption) via a crafted web site.

CWE-119 · Memory buffer bounds
Refsnvd.nist.gov
Federal remediation due 2022-04-18
CVE-2016-0189
2022-03-28
Microsoft Internet Explorer Memory Corruption VulnerabilityRansomware
Microsoft

The Microsoft JScript nd VBScript engines, as used in Internet Explorer and other products, allow attackers to execute remote code or cause a denial of service (memory corruption) via a crafted web site.

CWE-119 · Memory buffer bounds
Refsnvd.nist.gov
Federal remediation due 2022-04-18
CVE-2016-0151
2022-03-28
Microsoft Windows CSRSS Security Feature Bypass VulnerabilityRansomware
Microsoft / Client-Server Run-time Subsystem (CSRSS)

The Client-Server Run-time Subsystem (CSRSS) in Microsoft mismanages process tokens, which allows local users to gain privileges via a crafted application.

CWE-264 · Permissions and access control
Refsnvd.nist.gov
Federal remediation due 2022-04-18
Prev22 / 34Next