Rosetta Intel
Datasets/KEV CatalogThreat ActorsAttack Surface
Rosetta Lab ↗Blur Horizon LLC
Datasets

KEV Catalog

CISA, queryable

Known exploited vulnerabilities as a queryable table — by CVE, vendor or product.

1685 entries·352 Ransomware·Updated 2026-08-27

1685 results·Page 24 / 34

CVE-2017-12617
2022-03-25
Apache Tomcat Remote Code Execution Vulnerability
Apache

When running Apache Tomcat, it is possible to upload a JSP file to the server via a specially crafted request. This JSP could then be requested and any code it contained would be executed by the server.

CWE-434 · Unrestricted file upload
Refsnvd.nist.gov
Federal remediation due 2022-04-15
CVE-2017-12615
2022-03-25
Apache Tomcat on Windows Remote Code Execution VulnerabilityRansomware
Apache

When running Apache Tomcat on Windows with HTTP PUTs enabled, it is possible to upload a JSP file to the server via a specially crafted request. This JSP could then be requested and any code it contained would be executed by the server.

CWE-434 · Unrestricted file upload
Refsnvd.nist.gov
Federal remediation due 2022-04-15
CVE-2017-0146
2022-03-25
Microsoft Windows SMB Remote Code Execution VulnerabilityRansomware
Microsoft

The SMBv1 server in Microsoft Windows allows remote attackers to perform remote code execution.

CWE-20 · Improper input validation
Refsnvd.nist.gov
Federal remediation due 2022-04-15
CVE-2016-7892
2022-03-25
Adobe Flash Player Use-After-Free Vulnerability
Adobe

Adobe Flash Player has an exploitable use-after-free vulnerability in the TextField class.

CWE-416 · Use after free
Refsnvd.nist.gov
Federal remediation due 2022-04-15
CVE-2016-4171
2022-03-25
Adobe Flash Player Remote Code Execution Vulnerability
Adobe

Unspecified vulnerability in Adobe Flash Player allows for remote code execution.

Refsnvd.nist.gov
Federal remediation due 2022-04-15
CVE-2016-1555
2022-03-25
NETGEAR Multiple WAP Devices Command Injection Vulnerability
NETGEAR / Wireless Access Point (WAP) Devices

Multiple NETGEAR Wireless Access Point devices allows unauthenticated web pages to pass form input directly to the command-line interface. Exploitation allows for arbitrary code execution.

CWE-77 · Command injection
Refsnvd.nist.gov
Federal remediation due 2022-04-15
CVE-2016-11021
2022-03-25
D-Link DCS-930L Devices OS Command Injection Vulnerability
D-Link

setSystemCommand on D-Link DCS-930L devices allows a remote attacker to execute code via an OS command.

CWE-78 · OS command injection
Refsnvd.nist.gov
Federal remediation due 2022-04-15
CVE-2016-10174
2022-03-25
NETGEAR WNR2000v5 Router Buffer Overflow Vulnerability
NETGEAR

The NETGEAR WNR2000v5 router contains a buffer overflow which can be exploited to achieve remote code execution.

CWE-119 · Memory buffer bounds
Refsnvd.nist.gov
Federal remediation due 2022-04-15
CVE-2016-0752
2022-03-25
Ruby on Rails Directory Traversal Vulnerability
Rails

Directory traversal vulnerability in Action View in Ruby on Rails allows remote attackers to read arbitrary files.

CWE-22 · Path traversal
Refsnvd.nist.gov
Federal remediation due 2022-04-15
CVE-2015-4068
2022-03-25
Arcserve Unified Data Protection (UDP) Directory Traversal Vulnerability
Arcserve

Directory traversal vulnerability in Arcserve UDP allows remote attackers to obtain sensitive information or cause a denial of service.

CWE-22 · Path traversal
Refsnvd.nist.gov
Federal remediation due 2022-04-15
CVE-2015-3035
2022-03-25
TP-Link Multiple Archer Devices Directory Traversal Vulnerability
TP-Link

Directory traversal vulnerability in multiple TP-Link Archer devices allows remote attackers to read arbitrary files via a .. (dot dot) in the PATH_INFO to login/.

CWE-22 · Path traversal
Refsnvd.nist.gov
Federal remediation due 2022-04-15
CVE-2015-1427
2022-03-25
Elasticsearch Groovy Scripting Engine Remote Code Execution Vulnerability
Elastic

The Groovy scripting engine in Elasticsearch allows remote attackers to bypass the sandbox protection mechanism and execute arbitrary shell commands.

CWE-284 · Improper access control
Refsnvd.nist.gov
Federal remediation due 2022-04-15
CVE-2015-1187
2022-03-25
D-Link and TRENDnet Multiple Devices Remote Code Execution Vulnerability
D-Link and TRENDnet

The ping tool in multiple D-Link and TRENDnet devices allow remote attackers to perform remote code execution.

CWE-287 · Improper authentication
Refsnvd.nist.gov
Federal remediation due 2022-04-15
CVE-2015-0666
2022-03-25
Cisco Prime Data Center Network Manager (DCNM) Directory Traversal Vulnerability
Cisco

Directory traversal vulnerability in the fmserver servlet in Cisco Prime Data Center Network Manager (DCNM) allows remote attackers to read arbitrary files.

CWE-22 · Path traversal
Refsnvd.nist.gov
Federal remediation due 2022-04-15
CVE-2014-6332
2022-03-25
Microsoft Windows Object Linking & Embedding (OLE) Automation Array Remote Code Execution Vulnerability
Microsoft

OleAut32.dll in OLE in Microsoft Windows allows remote attackers to remotely execute code via a crafted web site.

CWE-119 · Memory buffer bounds
Refsnvd.nist.gov
Federal remediation due 2022-04-15
CVE-2014-6324
2022-03-25
Microsoft Kerberos Key Distribution Center (KDC) Privilege Escalation Vulnerability
Microsoft

The Kerberos Key Distribution Center (KDC) in Microsoft allows remote authenticated domain users to obtain domain administrator privileges.

CWE-264 · Permissions and access control
Refsnvd.nist.gov
Federal remediation due 2022-04-15
CVE-2014-6287
2022-03-25
Rejetto HTTP File Server (HFS) Remote Code Execution Vulnerability
Rejetto

The findMacroMarker function in parserLib.pas in Rejetto HTTP File Server (HFS or HttpFileServer) allows remote attackers to execute arbitrary programs.

CWE-94 · Code injection
Refsnvd.nist.gov
Federal remediation due 2022-04-15
CVE-2014-3120
2022-03-25
Elasticsearch Remote Code Execution Vulnerability
Elastic

Elasticsearch enables dynamic scripting, which allows remote attackers to execute arbitrary MVEL expressions and Java code.

CWE-284 · Improper access control
Refsnvd.nist.gov
Federal remediation due 2022-04-15
CVE-2014-0130
2022-03-25
Ruby on Rails Directory Traversal Vulnerability
Rails

Directory traversal vulnerability in actionpack/lib/abstract_controller/base.rb in the implicit-render implementation in Ruby on Rails allows remote attackers to read arbitrary files via a crafted request.

CWE-22 · Path traversal
Refsnvd.nist.gov
Federal remediation due 2022-04-15
CVE-2013-5223
2022-03-25
D-Link DSL-2760U Gateway Cross-Site Scripting Vulnerability
D-Link

A cross-site scripting (XSS) vulnerability exists in the D-Link DSL-2760U gateway, allowing remote authenticated users to inject arbitrary web script or HTML.

CWE-79 · Cross-site scripting
Refsnvd.nist.gov
Federal remediation due 2022-04-15
CVE-2013-4810
2022-03-25
HP Multiple Products Remote Code Execution Vulnerability
Hewlett Packard (HP) / ProCurve Manager (PCM), PCM+, Identity Driven Manager (IDM), and Application Lifecycle Management

HP ProCurve Manager (PCM), PCM+, Identity Driven Manager (IDM), and Application Lifecycle Management allow remote attackers to execute arbitrary code via a marshalled object to (1) EJBInvokerServlet or (2) JMXInvokerServlet.

CWE-94 · Code injection
Refsnvd.nist.gov
Federal remediation due 2022-04-15
CVE-2013-2251
2022-03-25
Apache Struts Improper Input Validation Vulnerability
Apache

Apache Struts allows remote attackers to execute arbitrary Object-Graph Navigation Language (OGNL) expressions.

CWE-20 · Improper input validation
Refsnvd.nist.gov
Federal remediation due 2022-04-15
CVE-2012-1823
2022-03-25
PHP-CGI Query String Parameter Vulnerability
PHP

sapi/cgi/cgi_main.c in PHP, when configured as a CGI script, does not properly handle query strings, which allows remote attackers to execute arbitrary code.

CWE-20 · Improper input validation
Refsnvd.nist.gov
Federal remediation due 2022-04-15
CVE-2010-4345
2022-03-25
Exim Privilege Escalation Vulnerability
Exim

Exim allows local users to gain privileges by leveraging the ability of the exim user account to specify an alternate configuration file with a directive that contains arbitrary commands.

CWE-264 · Permissions and access control
Refsnvd.nist.gov
Federal remediation due 2022-04-15
CVE-2010-4344
2022-03-25
Exim Heap-Based Buffer Overflow Vulnerability
Exim

Heap-based buffer overflow in the string_vformat function in string.c in Exim before 4.70 allows remote attackers to execute arbitrary code via an SMTP session.

CWE-119 · Memory buffer bounds
Refsnvd.nist.gov
Federal remediation due 2022-04-15
CVE-2010-3035
2022-03-25
Cisco IOS XR Border Gateway Protocol (BGP) Denial-of-Service Vulnerability
Cisco

Cisco IOS XR, when BGP is the configured routing feature, allows remote attackers to cause a denial-of-service (DoS).

CWE-20 · Improper input validation
Refsnvd.nist.gov
Federal remediation due 2022-04-15
CVE-2010-2861
2022-03-25
Adobe ColdFusion Directory Traversal VulnerabilityRansomware
Adobe

A directory traversal vulnerability exists in the administrator console in Adobe ColdFusion which allows remote attackers to read arbitrary files.

CWE-22 · Path traversal
Refsnvd.nist.gov
Federal remediation due 2022-04-15
CVE-2009-2055
2022-03-25
Cisco IOS XR Border Gateway Protocol (BGP) Denial-of-Service Vulnerability
Cisco

Cisco IOS XR,when BGP is the configured routing feature, allows remote attackers to cause a denial-of-service (DoS).

CWE-20 · Improper input validation
Refsnvd.nist.gov
Federal remediation due 2022-04-15
CVE-2009-1151
2022-03-25
phpMyAdmin Remote Code Execution Vulnerability
phpMyAdmin

Setup script used to generate configuration can be fooled using a crafted POST request to include arbitrary PHP code in generated configuration file.

CWE-94 · Code injection
Refsnvd.nist.gov
Federal remediation due 2022-04-15
CVE-2009-0927
2022-03-25
Adobe Reader and Adobe Acrobat Stack-Based Buffer Overflow Vulnerability
Adobe / Reader and Acrobat

Stack-based buffer overflow in Adobe Reader and Adobe Acrobat allows remote attackers to execute arbitrary code.

CWE-20 · Improper input validation
Refsnvd.nist.gov
Federal remediation due 2022-04-15
CVE-2005-2773
2022-03-25
HP OpenView Network Node Manager Remote Code Execution Vulnerability
Hewlett Packard (HP)

HP OpenView Network Node Manager could allow a remote attacker to execute arbitrary commands on the system.

Refsnvd.nist.gov
Federal remediation due 2022-04-15
CVE-2020-5135
2022-03-15
SonicWall SonicOS Buffer Overflow VulnerabilityRansomware
SonicWall

A buffer overflow vulnerability in SonicOS allows a remote attacker to cause Denial of Service (DoS) and potentially execute arbitrary code by sending a malicious request to the firewall.

CWE-120 · Classic buffer overflow
Refsnvd.nist.gov
Federal remediation due 2022-04-05
CVE-2019-1405
2022-03-15
Microsoft Windows Universal Plug and Play (UPnP) Service Privilege Escalation VulnerabilityRansomware
Microsoft

A privilege escalation vulnerability exists when the Windows UPnP service improperly allows COM object creation.

Refsnvd.nist.gov
Federal remediation due 2022-04-05
CVE-2019-1322
2022-03-15
Microsoft Windows Privilege Escalation VulnerabilityRansomware
Microsoft

A privilege escalation vulnerability exists when Windows improperly handles authentication requests. An attacker who successfully exploited this vulnerability could run processes in an elevated context.

Refsnvd.nist.gov
Federal remediation due 2022-04-05
CVE-2019-1315
2022-03-15
Microsoft Windows Error Reporting Manager Privilege Escalation VulnerabilityRansomware
Microsoft

A privilege escalation vulnerability exists when Windows Error Reporting manager improperly handles hard links. An attacker who successfully exploited this vulnerability could overwrite a targeted file leading to an elevated status.

CWE-59 · Link following
Refsnvd.nist.gov
Federal remediation due 2022-04-05
CVE-2019-1253
2022-03-15
Microsoft Windows AppX Deployment Server Privilege Escalation VulnerabilityRansomware
Microsoft

A privilege escalation vulnerability exists when the Windows AppX Deployment Server improperly handles junctions.

CWE-59 · Link following
Refsnvd.nist.gov
Federal remediation due 2022-04-05
CVE-2019-1132
2022-03-15
Microsoft Win32k Privilege Escalation Vulnerability
Microsoft

A privilege escalation vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory.

Refsnvd.nist.gov
Federal remediation due 2022-04-05
CVE-2019-1129
2022-03-15
Microsoft Windows AppX Deployment Service (AppXSVC) Privilege Escalation VulnerabilityRansomware
Microsoft

A privilege escalation vulnerability exists when Windows AppXSVC improperly handles hard links. An attacker who successfully exploited this vulnerability could run processes in an elevated context.

CWE-59 · Link following
Refsnvd.nist.gov
Federal remediation due 2022-04-05
CVE-2019-1069
2022-03-15
Microsoft Task Scheduler Privilege Escalation VulnerabilityRansomware
Microsoft

A privilege escalation vulnerability exists in the way the Task Scheduler Service validates certain file operations.

CWE-59 · Link following
Refsnvd.nist.gov
Federal remediation due 2022-04-05
CVE-2019-1064
2022-03-15
Microsoft Windows AppX Deployment Service (AppXSVC) Privilege Escalation VulnerabilityRansomware
Microsoft

A privilege escalation vulnerability exists when Windows AppXSVC improperly handles hard links. An attacker who successfully exploited this vulnerability could run processes in an elevated context.

CWE-59 · Link following
Refsnvd.nist.gov
Federal remediation due 2022-04-05
CVE-2019-0841
2022-03-15
Microsoft Windows AppX Deployment Service (AppXSVC) Privilege Escalation VulnerabilityRansomware
Microsoft

A privilege escalation vulnerability exists when Windows AppXSVC improperly handles hard links. An attacker who successfully exploited this vulnerability could run processes in an elevated context.

CWE-59 · Link following
Refsnvd.nist.gov
Federal remediation due 2022-04-05
CVE-2019-0543
2022-03-15
Microsoft Windows Privilege Escalation VulnerabilityRansomware
Microsoft

A privilege escalation vulnerability exists when Windows improperly handles authentication requests. An attacker who successfully exploited this vulnerability could run processes in an elevated context.

CWE-287 · Improper authentication
Refsnvd.nist.gov
Federal remediation due 2022-04-05
CVE-2018-8120
2022-03-15
Microsoft Win32k Privilege Escalation VulnerabilityRansomware
Microsoft

A privilege escalation vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory.

CWE-404
Refsnvd.nist.gov
Federal remediation due 2022-04-05
CVE-2017-0101
2022-03-15
Microsoft Windows Transaction Manager Privilege Escalation VulnerabilityRansomware
Microsoft

A privilege escalation vulnerability exists when the Windows Transaction Manager improperly handles objects in memory.

CWE-119 · Memory buffer bounds
Refsnvd.nist.gov
Federal remediation due 2022-04-05
CVE-2016-3309
2022-03-15
Microsoft Windows Kernel Privilege Escalation VulnerabilityRansomware
Microsoft

A privilege escalation vulnerability exists when the Windows kernel fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode.

CWE-264 · Permissions and access control
Refsnvd.nist.gov
Federal remediation due 2022-04-05
CVE-2015-2546
2022-03-15
Microsoft Win32k Memory Corruption VulnerabilityRansomware
Microsoft

The kernel-mode driver in Microsoft Windows OS and Server allows local users to gain privileges via a crafted application.

CWE-119 · Memory buffer bounds
Refsnvd.nist.gov
Federal remediation due 2022-04-05
CVE-2022-26486
2022-03-07
Mozilla Firefox Use-After-Free Vulnerability
Mozilla

Mozilla Firefox contains a use-after-free vulnerability in WebGPU IPC Framework which can be exploited to perform arbitrary code execution.

CWE-416 · Use after free
Refsnvd.nist.gov
Federal remediation due 2022-03-21
CVE-2022-26485
2022-03-07
Mozilla Firefox Use-After-Free Vulnerability
Mozilla

Mozilla Firefox contains a use-after-free vulnerability in XSLT parameter processing which can be exploited to perform arbitrary code execution.

CWE-416 · Use after free
Refsnvd.nist.gov
Federal remediation due 2022-03-21
CVE-2021-21973
2022-03-07
VMware vCenter Server and Cloud Foundation Server Side Request Forgery (SSRF) Vulnerability
VMware

VMware vCenter Server and Cloud Foundation Server contain a SSRF vulnerability due to improper validation of URLs in a vCenter Server plugin. This allows for information disclosure.

CWE-20 · Improper input validationCWE-918 · Server-side request forgery
Refsnvd.nist.gov
Federal remediation due 2022-03-21
CVE-2020-8218
2022-03-07
Pulse Connect Secure Code Injection Vulnerability
Pulse Secure

A code injection vulnerability exists in Pulse Connect Secure that allows an attacker to crafted a URI to perform an arbitrary code execution via the admin web interface.

CWE-94 · Code injection
Refsnvd.nist.gov
Federal remediation due 2022-09-07
Prev24 / 34Next