Rosetta Intel
Datasets/KEV CatalogThreat ActorsAttack Surface
Rosetta Lab ↗Blur Horizon LLC
Datasets

KEV Catalog

CISA, queryable

Known exploited vulnerabilities as a queryable table — by CVE, vendor or product.

1685 entries·352 Ransomware·Updated 2026-08-27

1685 results·Page 25 / 34

CVE-2019-11581
2022-03-07
Atlassian Jira Server and Data Center Server-Side Template Injection Vulnerability
Atlassian

Atlassian Jira Server and Data Center contain a server-side template injection vulnerability which can allow for remote code execution.

CWE-74
Refsnvd.nist.gov
Federal remediation due 2022-09-07
CVE-2017-6077
2022-03-07
NETGEAR DGN2200 Remote Code Execution Vulnerability
NETGEAR / Wireless Router DGN2200

NETGEAR DGN2200 wireless routers contain a vulnerability that allows for remote code execution.

CWE-78 · OS command injection
Refsnvd.nist.gov
Federal remediation due 2022-09-07
CVE-2016-6277
2022-03-07
NETGEAR Multiple Routers Remote Code Execution Vulnerability
NETGEAR

NETGEAR confirmed multiple routers allow unauthenticated web pages to pass form input directly to the command-line interface, permitting remote code execution.

CWE-352 · Cross-site request forgery
Refsnvd.nist.gov
Federal remediation due 2022-09-07
CVE-2013-0631
2022-03-07
Adobe ColdFusion Information Disclosure Vulnerability
Adobe

Adobe Coldfusion contains an unspecified vulnerability, which could result in information disclosure from a compromised server.

CWE-200 · Information exposure
Refsnvd.nist.gov
Federal remediation due 2022-09-07
CVE-2013-0629
2022-03-07
Adobe ColdFusion Directory Traversal Vulnerability
Adobe

Adobe Coldfusion contains a directory traversal vulnerability, which could permit an unauthorized user access to restricted directories.

CWE-264 · Permissions and access control
Refsnvd.nist.gov
Federal remediation due 2022-09-07
CVE-2013-0625
2022-03-07
Adobe ColdFusion Authentication Bypass Vulnerability
Adobe

Adobe Coldfusion contains an authentication bypass vulnerability, which could result in an unauthorized user gaining administrative access.

CWE-255
Refsnvd.nist.gov
Federal remediation due 2022-09-07
CVE-2009-3960
2022-03-07
Adobe BlazeDS Information Disclosure VulnerabilityRansomware
Adobe

Adobe BlazeDS, which is utilized in LifeCycle and Coldfusion, contains a vulnerability that allows for information disclosure.

Refsnvd.nist.gov
Federal remediation due 2022-09-07
CVE-2022-20708
2022-03-03
Cisco Small Business RV Series Routers Stack-based Buffer Overflow Vulnerability
Cisco / Small Business RV160, RV260, RV340, and RV345 Series Routers

A vulnerability in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code elevate privileges, execute arbitrary commands, bypass authentication and authorization protections, fetch and run unsigned software, or cause a denial of service (DoS).

CWE-121 · Stack buffer overflow
Refsnvd.nist.gov
Federal remediation due 2022-03-17
CVE-2022-20703
2022-03-03
Cisco Small Business RV Series Routers Stack-based Buffer Overflow Vulnerability
Cisco / Small Business RV160, RV260, RV340, and RV345 Series Routers

A vulnerability in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code elevate privileges, execute arbitrary commands, bypass authentication and authorization protections, fetch and run unsigned software, or cause a denial of service (DoS).

CWE-347
Refsnvd.nist.gov
Federal remediation due 2022-03-17
CVE-2022-20701
2022-03-03
Cisco Small Business RV Series Routers Stack-based Buffer Overflow Vulnerability
Cisco / Small Business RV160, RV260, RV340, and RV345 Series Routers

A vulnerability in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code elevate privileges, execute arbitrary commands, bypass authentication and authorization protections, fetch and run unsigned software, or cause a denial of service (DoS).

CWE-121 · Stack buffer overflow
Refsnvd.nist.gov
Federal remediation due 2022-03-17
CVE-2022-20700
2022-03-03
Cisco Small Business RV Series Routers Stack-based Buffer Overflow Vulnerability
Cisco / Small Business RV160, RV260, RV340, and RV345 Series Routers

A vulnerability in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code elevate privileges, execute arbitrary commands, bypass authentication and authorization protections, fetch and run unsigned software, or cause a denial of service (DoS).

CWE-121 · Stack buffer overflow
Refsnvd.nist.gov
Federal remediation due 2022-03-17
CVE-2022-20699
2022-03-03
Cisco Small Business RV Series Routers Stack-based Buffer Overflow Vulnerability
Cisco / Small Business RV160, RV260, RV340, and RV345 Series Routers

A vulnerability in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code elevate privileges, execute arbitrary commands, bypass authentication and authorization protections, fetch and run unsigned software, or cause a denial of service (DoS).

CWE-785
Refsnvd.nist.gov
Federal remediation due 2022-03-17
CVE-2021-41379
2022-03-03
Microsoft Windows Installer Privilege Escalation VulnerabilityRansomware
Microsoft

Microsoft Windows Installer contains an unspecified vulnerability that allows for privilege escalation.

CWE-1386
Refsnvd.nist.gov
Federal remediation due 2022-03-17
CVE-2020-1938
2022-03-03
Apache Tomcat Improper Privilege Management Vulnerability
Apache

Apache Tomcat treats Apache JServ Protocol (AJP) connections as having higher trust than, for example, a similar HTTP connection. If such connections are available to an attacker, they can be exploited.

Refsnvd.nist.gov
Federal remediation due 2022-03-17
CVE-2020-11899
2022-03-03
Treck TCP/IP stack Out-of-Bounds Read Vulnerability
Treck TCP/IP stack / IPv6

The Treck TCP/IP stack contains an IPv6 out-of-bounds read vulnerability.

CWE-125 · Out-of-bounds read
Refsnvd.nist.gov
Federal remediation due 2022-03-17
CVE-2019-16928
2022-03-03
Exim Out-of-bounds Write Vulnerability
Exim / Exim Internet Mailer

Exim contains an out-of-bounds write vulnerability which can allow for remote code execution.

CWE-787 · Out-of-bounds write
Refsnvd.nist.gov
Federal remediation due 2022-03-17
CVE-2019-1652
2022-03-03
Cisco Small Business Routers Improper Input Validation Vulnerability
Cisco / Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers

A vulnerability in the web-based management interface of Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers could allow an authenticated, remote attacker with administrative privileges on an affected device to execute arbitrary commands.

CWE-20 · Improper input validation
Refsnvd.nist.gov
Federal remediation due 2022-03-17
CVE-2019-1297
2022-03-03
Microsoft Excel Remote Code Execution Vulnerability
Microsoft

A remote code execution vulnerability exists in Microsoft Excel when the software fails to properly handle objects in memory.

Refsnvd.nist.gov
Federal remediation due 2022-03-17
CVE-2018-8581
2022-03-03
Microsoft Exchange Server Privilege Escalation VulnerabilityRansomware
Microsoft

A privilege escalation vulnerability exists in Microsoft Exchange Server. An attacker who successfully exploited this vulnerability could attempt to impersonate any other user of the Exchange server.

Refsnvd.nist.gov
Federal remediation due 2022-03-17
CVE-2018-8298
2022-03-03
ChakraCore Scripting Engine Type Confusion Vulnerability
ChakraCore

The ChakraCore scripting engine contains a type confusion vulnerability which can allow for remote code execution.

CWE-843 · Type confusion
Refsnvd.nist.gov
Federal remediation due 2022-03-17
CVE-2018-0180
2022-03-03
Cisco IOS Software Denial-of-Service Vulnerability
Cisco

A vulnerability in the Login Enhancements (Login Block) feature of Cisco IOS Software could allow an unauthenticated, remote attacker to trigger a reload of an affected system, resulting in a denial of service (DoS) condition.

CWE-399 · Resource management
Refsnvd.nist.gov
Federal remediation due 2022-03-17
CVE-2018-0179
2022-03-03
Cisco IOS Software Denial-of-Service Vulnerability
Cisco

A vulnerability in the Login Enhancements (Login Block) feature of Cisco IOS Software could allow an unauthenticated, remote attacker to trigger a reload of an affected system, resulting in a denial of service (DoS) condition.

CWE-399 · Resource management
Refsnvd.nist.gov
Federal remediation due 2022-03-17
CVE-2018-0175
2022-03-03
Cisco IOS, XR, and XE Software Buffer Overflow Vulnerability
Cisco

Format string vulnerability in the Link Layer Discovery Protocol (LLDP) subsystem of Cisco IOS Software, Cisco IOS XE Software, and Cisco IOS XR Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition or execute arbitrary code with elevated privileges on an affected device.

CWE-119 · Memory buffer bounds
Refsnvd.nist.gov
Federal remediation due 2022-03-17
CVE-2018-0174
2022-03-03
Cisco IOS Software and Cisco IOS XE Software Improper Input Validation Vulnerability
Cisco

A vulnerability in the DHCP option 82 encapsulation functionality of Cisco IOS Software and Cisco IOS XE Software could allow for denial-of-service (DoS).

CWE-20 · Improper input validation
Refsnvd.nist.gov
Federal remediation due 2022-03-17
CVE-2018-0173
2022-03-03
Cisco IOS and IOS XE Software Improper Input Validation Vulnerability
Cisco

A vulnerability in the Cisco IOS Software and Cisco IOS XE Software function that restores encapsulated option 82 information in DHCP Version 4 (DHCPv4) packets can allow for denial-of-service (DoS).

CWE-20 · Improper input validation
Refsnvd.nist.gov
Federal remediation due 2022-03-17
CVE-2018-0172
2022-03-03
Cisco IOS and IOS XE Software Improper Input Validation Vulnerability
Cisco

A vulnerability in the DHCP option 82 encapsulation functionality of Cisco IOS Software and Cisco IOS XE Software could allow for denial-of-service (DoS).

CWE-20 · Improper input validation
Refsnvd.nist.gov
Federal remediation due 2022-03-17
CVE-2018-0167
2022-03-03
Cisco IOS, XR, and XE Software Buffer Overflow Vulnerability
Cisco

There is a buffer overflow vulnerability in the Link Layer Discovery Protocol (LLDP) subsystem of Cisco IOS Software, Cisco IOS XE Software, and Cisco IOS XR Software which could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition or execute arbitrary code.

CWE-119 · Memory buffer bounds
Refsnvd.nist.gov
Federal remediation due 2022-03-17
CVE-2018-0161
2022-03-03
Cisco IOS Software Resource Management Errors Vulnerability
Cisco

A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS Software running on certain models of Cisco Catalyst Switches could allow an authenticated, remote attacker to cause a denial-of-service (DoS) condition.

CWE-399 · Resource management
Refsnvd.nist.gov
Federal remediation due 2022-03-17
CVE-2018-0159
2022-03-03
Cisco IOS and XE Software Internet Key Exchange Version 1 Denial-of-Service Vulnerability
Cisco / IOS Software and Cisco IOS XE Software

A vulnerability in the implementation of Internet Key Exchange Version 1 (IKEv1) functionality in Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial-of-service (DoS) condition.

CWE-20 · Improper input validation
Refsnvd.nist.gov
Federal remediation due 2022-03-17
CVE-2018-0158
2022-03-03
Cisco IOS and XE Software Internet Key Exchange Memory Leak Vulnerability
Cisco / IOS Software and Cisco IOS XE Software

A vulnerability in the implementation of Internet Key Exchange Version 1 (IKEv1) functionality in Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial-of-service (DoS) condition.

CWE-20 · Improper input validation
Refsnvd.nist.gov
Federal remediation due 2022-03-17
CVE-2018-0156
2022-03-03
Cisco IOS Software and Cisco IOS XE Software Smart Install Denial-of-Service Vulnerability
Cisco

A vulnerability in the Smart Install feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to trigger a reload of an affected device, resulting in a denial-of-service (DoS) condition.

CWE-399 · Resource management
Refsnvd.nist.gov
Federal remediation due 2022-03-17
CVE-2018-0155
2022-03-03
Cisco Catalyst Bidirectional Forwarding Detection Denial-of-Service Vulnerability
Cisco / Catalyst 4500 Series Switches and Cisco Catalyst 4500-X Series Switches

A vulnerability in the Bidirectional Forwarding Detection (BFD) offload implementation of Cisco Catalyst 4500 Series Switches and Cisco Catalyst 4500-X Series Switches could allow an unauthenticated, remote attacker to cause a crash of the iosd process, causing a denial-of-service (DoS) condition.

CWE-388
Refsnvd.nist.gov
Federal remediation due 2022-03-17
CVE-2018-0154
2022-03-03
Cisco IOS Software Integrated Services Module for VPN Denial-of-Service Vulnerability
Cisco

A vulnerability in the crypto engine of the Cisco Integrated Services Module for VPN (ISM-VPN) running Cisco IOS Software could allow an unauthenticated, remote attacker to cause a denial-of-service (DoS) condition.

CWE-399 · Resource management
Refsnvd.nist.gov
Federal remediation due 2022-03-17
CVE-2018-0151
2022-03-03
Cisco IOS Software and Cisco IOS XE Software Quality of Service Remote Code Execution Vulnerability
Cisco / IOS and IOS XE Software

A vulnerability in the quality of service (QoS) subsystem of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition or execute arbitrary code with elevated privileges.

CWE-119 · Memory buffer bounds
Refsnvd.nist.gov
Federal remediation due 2022-03-17
CVE-2017-8540
2022-03-03
Microsoft Malware Protection Engine Improper Restriction of Operations Vulnerability
Microsoft

The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016, Microsoft Exchange Server 2013 and 2016, does not properly scan a specially crafted file leading to memory corruption. aka "Microsoft Malware Protection Engine Remote Code Execution Vulnerability".

CWE-119 · Memory buffer bounds
Refsnvd.nist.gov
Federal remediation due 2022-03-24
CVE-2017-6744
2022-03-03
Cisco IOS Software SNMP Remote Code Execution Vulnerability
Cisco

The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS 1 contains a vulnerability that could allow an authenticated, remote attacker to remotely execute code on an affected system or cause an affected system to reload. An attacker could exploit these vulnerabilities by sending a crafted SNMP packet to an affected system via IPv4 or IPv6.

CWE-119 · Memory buffer bounds
Refsnvd.nist.gov
Federal remediation due 2022-03-24
CVE-2017-6743
2022-03-03
Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability
Cisco

The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE contains a vulnerability that could allow an authenticated, remote attacker to remotely execute code.

CWE-119 · Memory buffer bounds
Refsnvd.nist.gov
Federal remediation due 2022-03-24
CVE-2017-6740
2022-03-03
Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability
Cisco

The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE contains a vulnerability that could allow an authenticated, remote attacker to remotely execute code on an affected system or cause an affected system to reload.

CWE-119 · Memory buffer bounds
Refsnvd.nist.gov
Federal remediation due 2022-03-24
CVE-2017-6739
2022-03-03
Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability
Cisco

The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE contains a vulnerability that could allow an authenticated, remote attacker to remotely execute code on an affected system or cause an affected system to reload.

CWE-119 · Memory buffer bounds
Refsnvd.nist.gov
Federal remediation due 2022-03-24
CVE-2017-6738
2022-03-03
Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability
Cisco

The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE contains a vulnerability that could allow an authenticated, remote attacker to remotely execute code.

CWE-119 · Memory buffer bounds
Refsnvd.nist.gov
Federal remediation due 2022-03-24
CVE-2017-6737
2022-03-03
Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability
Cisco

The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE contains a vulnerability that could allow an authenticated, remote attacker to remotely execute code.

CWE-119 · Memory buffer bounds
Refsnvd.nist.gov
Federal remediation due 2022-03-24
CVE-2017-6736
2022-03-03
Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability
Cisco

The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE contains a vulnerability that could allow an authenticated, remote attacker to remotely execute code.

CWE-119 · Memory buffer bounds
Refsnvd.nist.gov
Federal remediation due 2022-03-24
CVE-2017-6663
2022-03-03
Cisco IOS Software and Cisco IOS XE Software Denial-of-Service Vulnerability
Cisco / IOS and IOS XE Software

A vulnerability in the Autonomic Networking feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to cause autonomic nodes of an affected system to reload, resulting in denial-of-service (DoS).

Refsnvd.nist.gov
Federal remediation due 2022-03-24
CVE-2017-6627
2022-03-03
Cisco IOS Software and Cisco IOS XE Software UDP Packet Processing Denial-of-Service Vulnerability
Cisco / IOS and IOS XE Software

A vulnerability in the UDP processing code of Cisco IOS and IOS XE could allow an unauthenticated, remote attacker to cause the input queue of an affected system to hold UDP packets, causing an interface queue wedge and denial of service.

CWE-399 · Resource management
Refsnvd.nist.gov
Federal remediation due 2022-03-24
CVE-2017-12319
2022-03-03
Cisco IOS XE Software Ethernet Virtual Private Network Border Gateway Protocol Denial-of-Service Vulnerability
Cisco

A vulnerability in the Border Gateway Protocol (BGP) over an Ethernet Virtual Private Network (EVPN) for Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause the device to reload, resulting in a denial of service (DoS) condition, or potentially corrupt the BGP routing table, which could result in network instability.

CWE-20 · Improper input validation
Refsnvd.nist.gov
Federal remediation due 2022-03-24
CVE-2017-12240
2022-03-03
Cisco IOS and IOS XE Software DHCP Remote Code Execution Vulnerability
Cisco

The Dynamic Host Configuration Protocol (DHCP) relay subsystem of Cisco IOS and Cisco IOS XE Software contains a vulnerability that could allow an unauthenticated, remote attacker to execute arbitrary code and gain full control of an affected system.

CWE-20 · Improper input validation
Refsnvd.nist.gov
Federal remediation due 2022-03-24
CVE-2017-12238
2022-03-03
Cisco Catalyst 6800 Series Switches VPLS Denial-of-Service Vulnerability
Cisco

A vulnerability in the Virtual Private LAN Service (VPLS) code of Cisco IOS for Cisco Catalyst 6800 Series Switches could allow an unauthenticated, adjacent attacker to cause a denial of service.

CWE-399 · Resource management
Refsnvd.nist.gov
Federal remediation due 2022-03-24
CVE-2017-12237
2022-03-03
Cisco IOS and IOS XE Software Internet Key Exchange Denial-of-Service Vulnerability
Cisco

A vulnerability in the Internet Key Exchange Version 2 (IKEv2) module of Cisco IOS and Cisco IOS XE could allow an unauthenticated, remote attacker to cause high CPU utilization, traceback messages, or a reload of an affected device that leads to a denial of service.

CWE-399 · Resource management
Refsnvd.nist.gov
Federal remediation due 2022-03-24
CVE-2017-12235
2022-03-03
Cisco IOS Software for Cisco Industrial Ethernet Switches PROFINET Denial-of-Service Vulnerability
Cisco

A vulnerability in the implementation of the PROFINET Discovery and Configuration Protocol (PN-DCP) for Cisco IOS could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial of service.

CWE-20 · Improper input validation
Refsnvd.nist.gov
Federal remediation due 2022-03-24
CVE-2017-12234
2022-03-03
Cisco IOS Software Common Industrial Protocol Request Denial-of-Service Vulnerability
Cisco

There is a vulnerability in the implementation of the Common Industrial Protocol (CIP) feature in Cisco IOS could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial of service.

CWE-20 · Improper input validation
Refsnvd.nist.gov
Federal remediation due 2022-03-24
Prev25 / 34Next