Rosetta Intel
Datasets/KEV CatalogThreat ActorsAttack Surface
Rosetta Lab ↗Blur Horizon LLC
Datasets

KEV Catalog

CISA, queryable

Known exploited vulnerabilities as a queryable table — by CVE, vendor or product.

1685 entries·352 Ransomware·Updated 2026-08-27

1685 results·Page 27 / 34

CVE-2004-0210
2022-03-03
Microsoft Windows Privilege Escalation Vulnerability
Microsoft

A privilege elevation vulnerability exists in the POSIX subsystem. This vulnerability could allow a logged on user to take complete control of the system.

CWE-120 · Classic buffer overflow
Refsnvd.nist.gov
Federal remediation due 2022-03-24
CVE-2002-0367
2022-03-03
Microsoft Windows Privilege Escalation Vulnerability
Microsoft

smss.exe debugging subsystem in Microsoft Windows does not properly authenticate programs that connect to other programs, which allows local users to gain administrator or SYSTEM privileges.

Refsnvd.nist.gov
Federal remediation due 2022-03-24
CVE-2022-24682
2022-02-25
Synacor Zimbra Collaborate Suite (ZCS) Cross-Site Scripting VulnerabilityRansomware
Synacor

Synacor Zimbra Collaboration Suite (ZCS) contains a cross-site scripting (XSS) vulnerability in the Calendar feature that allows an attacker to execute arbitrary code.

CWE-79 · Cross-site scriptingCWE-116
Refsnvd.nist.gov
Federal remediation due 2022-03-11
CVE-2017-8570
2022-02-25
Microsoft Office Remote Code Execution Vulnerability
Microsoft

A remote code execution vulnerability exists in Microsoft Office software when it fails to properly handle objects in memory.

Refsnvd.nist.gov
Federal remediation due 2022-08-25
CVE-2017-0222
2022-02-25
Microsoft Internet Explorer Remote Code Execution Vulnerability
Microsoft

A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory.

CWE-119 · Memory buffer bounds
Refsnvd.nist.gov
Federal remediation due 2022-08-25
CVE-2014-6352
2022-02-25
Microsoft Windows Code Injection Vulnerability
Microsoft

Microsoft Windows allow remote attackers to execute arbitrary code via a crafted OLE object.

CWE-94 · Code injection
Refsnvd.nist.gov
Federal remediation due 2022-08-25
CVE-2022-23134
2022-02-22
Zabbix Frontend Improper Access Control Vulnerability
Zabbix

Malicious actors can pass step checks and potentially change the configuration of Zabbix Frontend.

CWE-284 · Improper access control
Refsnvd.nist.gov
Federal remediation due 2022-03-08
CVE-2022-23131
2022-02-22
Zabbix Frontend Authentication Bypass Vulnerability
Zabbix

Unsafe client-side session storage leading to authentication bypass/instance takeover via Zabbix Frontend with configured SAML.

CWE-290
Refsnvd.nist.gov
Federal remediation due 2022-03-08
CVE-2022-24086
2022-02-15
Adobe Commerce and Magento Open Source Improper Input Validation Vulnerability
Adobe

Adobe Commerce and Magento Open Source contain an improper input validation vulnerability which can allow for arbitrary code execution.

CWE-20 · Improper input validation
Refsnvd.nist.gov
Federal remediation due 2022-03-01
CVE-2022-0609
2022-02-15
Google Chromium Animation Use-After-Free Vulnerability
Google

Google Chromium Animation contains a use-after-free vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

CWE-416 · Use after free
Refsnvd.nist.gov
Federal remediation due 2022-03-01
CVE-2019-0752
2022-02-15
Microsoft Internet Explorer Type Confusion VulnerabilityRansomware
Microsoft

A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer

CWE-843 · Type confusion
Refsnvd.nist.gov
Federal remediation due 2022-08-15
CVE-2018-8174
2022-02-15
Microsoft Windows VBScript Engine Out-of-Bounds Write VulnerabilityRansomware
Microsoft

A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows VBScript Engine Remote Code Execution"

CWE-787 · Out-of-bounds write
Refsnvd.nist.gov
Federal remediation due 2022-08-15
CVE-2018-20250
2022-02-15
WinRAR Absolute Path Traversal VulnerabilityRansomware
RARLAB

WinRAR Absolute Path Traversal vulnerability leads to Remote Code Execution

CWE-36
Refsnvd.nist.gov
Federal remediation due 2022-08-15
CVE-2018-15982
2022-02-15
Adobe Flash Player Use-After-Free VulnerabilityRansomware
Adobe

Adobe Flash Player com.adobe.tvsdk.mediacore.metadata Use After Free Vulnerability

CWE-416 · Use after free
Refsnvd.nist.gov
Federal remediation due 2022-08-15
CVE-2017-9841
2022-02-15
PHPUnit Command Injection Vulnerability
PHPUnit

PHPUnit allows remote attackers to execute arbitrary PHP code via HTTP POST data beginning with a "<?php " substring, as demonstrated by an attack on a site with an exposed /vendor folder, i.e., external access to the /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php URI.

CWE-94 · Code injection
Refsnvd.nist.gov
Federal remediation due 2022-08-15
CVE-2014-1761
2022-02-15
Microsoft Word Memory Corruption Vulnerability
Microsoft

Microsoft Word contains a memory corruption vulnerability which when exploited could allow for remote code execution.

CWE-119 · Memory buffer bounds
Refsnvd.nist.gov
Federal remediation due 2022-08-15
CVE-2013-3906
2022-02-15
Microsoft Graphics Component Memory Corruption Vulnerability
Microsoft

Microsoft Graphics Component contains a memory corruption vulnerability which can allow for remote code execution.

CWE-94 · Code injection
Refsnvd.nist.gov
Federal remediation due 2022-08-15
CVE-2022-22620
2022-02-11
Apple iOS, iPadOS, and macOS Webkit Use-After-Free Vulnerability
Apple

Apple iOS, iPadOS, and macOS WebKit contain a use-after-free vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing.

CWE-416 · Use after free
Refsnvd.nist.gov
Federal remediation due 2022-02-25
CVE-2021-36934
2022-02-10
Microsoft Windows SAM Local Privilege Escalation Vulnerability
Microsoft

If a Volume Shadow Copy (VSS) shadow copy of the system drive is available, users can read the SAM file which would allow any user to escalate privileges to SYSTEM level.

CWE-1220
Refsnvd.nist.gov
Federal remediation due 2022-02-24
CVE-2020-0796
2022-02-10
Microsoft SMBv3 Remote Code Execution VulnerabilityRansomware
Microsoft

A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol handles certain requests. An attacker who successfully exploited the vulnerability could gain the ability to execute code on the target server or client.

CWE-119 · Memory buffer bounds
Refsnvd.nist.gov
Federal remediation due 2022-08-10
CVE-2018-1000861
2022-02-10
Jenkins Stapler Web Framework Deserialization of Untrusted Data Vulnerability
Jenkins

A code execution vulnerability exists in the Stapler web framework used by Jenkins

CWE-502 · Deserialization of untrusted data
Refsnvd.nist.gov
Federal remediation due 2022-08-10
CVE-2017-9791
2022-02-10
Apache Struts 1 Improper Input Validation Vulnerability
Apache

The Struts 1 plugin in Apache Struts might allow remote code execution via a malicious field value passed in a raw message to the ActionMessage.

CWE-20 · Improper input validation
Refsnvd.nist.gov
Federal remediation due 2022-08-10
CVE-2017-8464
2022-02-10
Microsoft Windows Shell (.lnk) Remote Code Execution Vulnerability
Microsoft

Windows Shell in multiple versions of Microsoft Windows allows local users or remote attackers to execute arbitrary code via a crafted .LNK file

Refsnvd.nist.gov
Federal remediation due 2022-08-10
CVE-2017-10271
2022-02-10
Oracle Corporation WebLogic Server Remote Code Execution VulnerabilityRansomware
Oracle

Oracle Corporation WebLogic Server contains a vulnerability that allows for remote code execution.

Refsnvd.nist.gov
Federal remediation due 2022-08-10
CVE-2017-0263
2022-02-10
Microsoft Win32k Privilege Escalation Vulnerability
Microsoft

Microsoft Win32k contains a privilege escalation vulnerability due to the Windows kernel-mode driver failing to properly handle objects in memory.

CWE-416 · Use after free
Refsnvd.nist.gov
Federal remediation due 2022-08-10
CVE-2017-0262
2022-02-10
Microsoft Office Remote Code Execution Vulnerability
Microsoft

A remote code execution vulnerability exists in Microsoft Office.

Refsnvd.nist.gov
Federal remediation due 2022-08-10
CVE-2017-0145
2022-02-10
Microsoft SMBv1 Remote Code Execution VulnerabilityRansomware
Microsoft

The SMBv1 server in multiple Microsoft Windows versions allows remote attackers to execute arbitrary code via crafted packets.

CWE-20 · Improper input validation
Refsnvd.nist.gov
Federal remediation due 2022-08-10
CVE-2017-0144
2022-02-10
Microsoft SMBv1 Remote Code Execution VulnerabilityRansomware
Microsoft

The SMBv1 server in multiple Microsoft Windows versions allows remote attackers to execute arbitrary code via crafted packets.

CWE-20 · Improper input validation
Refsnvd.nist.gov
Federal remediation due 2022-08-10
CVE-2016-3088
2022-02-10
Apache ActiveMQ Improper Input Validation Vulnerability
Apache

The Fileserver web application in Apache ActiveMQ allows remote attackers to upload and execute arbitrary files via an HTTP PUT followed by an HTTP MOVE request

CWE-20 · Improper input validation
Refsnvd.nist.gov
Federal remediation due 2022-08-10
CVE-2015-2051
2022-02-10
D-Link DIR-645 Router Remote Code Execution Vulnerability
D-Link

D-Link DIR-645 Wired/Wireless Router allows remote attackers to execute arbitrary commands via a GetDeviceSettings action to the HNAP interface.

CWE-77 · Command injection
Refsnvd.nist.gov
Federal remediation due 2022-08-10
CVE-2015-1635
2022-02-10
Microsoft HTTP.sys Remote Code Execution Vulnerability
Microsoft

Microsoft HTTP protocol stack (HTTP.sys) contains a vulnerability that allows for remote code execution.

CWE-94 · Code injection
Refsnvd.nist.gov
Federal remediation due 2022-08-10
CVE-2015-1130
2022-02-10
Apple OS X Authentication Bypass Vulnerability
Apple

The XPC implementation in Admin Framework in Apple OS X before 10.10.3 allows local users to bypass authentication and obtain admin privileges.

CWE-254
Refsnvd.nist.gov
Federal remediation due 2022-08-10
CVE-2014-4404
2022-02-10
Apple OS X Heap-Based Buffer Overflow Vulnerability
Apple

Heap-based buffer overflow in IOHIDFamily in Apple OS X, which affects, iOS before 8 and Apple TV before 7, allows attackers to execute arbitrary code in a privileged context.

CWE-119 · Memory buffer bounds
Refsnvd.nist.gov
Federal remediation due 2022-08-10
CVE-2022-21882
2022-02-04
Microsoft Win32k Privilege Escalation VulnerabilityRansomware
Microsoft

Microsoft Win32k contains an unspecified vulnerability that allows for privilege escalation.

CWE-787 · Out-of-bounds write
Refsnvd.nist.gov
Federal remediation due 2022-02-18
CVE-2022-22587
2022-01-28
Apple Memory Corruption Vulnerability
Apple / iOS and macOS

Apple IOMobileFrameBuffer contains a memory corruption vulnerability which can allow a malicious application to execute arbitrary code with kernel privileges.

CWE-20 · Improper input validationCWE-787 · Out-of-bounds write
Refsnvd.nist.gov
Federal remediation due 2022-02-11
CVE-2021-20038
2022-01-28
SonicWall SMA 100 Appliances Stack-Based Buffer Overflow VulnerabilityRansomware
SonicWall

SonicWall SMA 100 devies are vulnerable to an unauthenticated stack-based buffer overflow vulnerability where exploitation can result in code execution.

CWE-121 · Stack buffer overflow
Refsnvd.nist.gov
Federal remediation due 2022-02-11
CVE-2020-5722
2022-01-28
Grandstream Networks UCM6200 Series SQL Injection Vulnerability
Grandstream

Grandstream UCM6200 series is vulnerable to an unauthenticated remote SQL injection via crafted HTTP request. Exploitation can allow for code execution as root.

CWE-89 · SQL injection
Refsnvd.nist.gov
Federal remediation due 2022-07-28
CVE-2020-0787
2022-01-28
Microsoft Windows Background Intelligent Transfer Service (BITS) Improper Privilege Management VulnerabilityRansomware
Microsoft

Microsoft Windows BITS is vulnerable to to a privilege elevation vulnerability if it improperly handles symbolic links. An actor can exploit this vulnerability to execute arbitrary code with system-level privileges.

CWE-269 · Improper privilege managementCWE-59 · Link following
Refsnvd.nist.gov
Federal remediation due 2022-07-28
CVE-2017-5689
2022-01-28
Intel Active Management Technology (AMT), Small Business Technology (SBT), and Standard Manageability Privilege Escalation Vulnerability
Intel

Intel products contain a vulnerability which can allow attackers to perform privilege escalation.

Refsnvd.nist.gov
Federal remediation due 2022-07-28
CVE-2014-7169
2022-01-28
GNU Bourne-Again Shell (Bash) Arbitrary Code Execution Vulnerability
GNU

GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute code. This CVE correctly remediates the vulnerability in CVE-2014-6271.

CWE-78 · OS command injection
Refsnvd.nist.gov
Federal remediation due 2022-07-28
CVE-2014-6271
2022-01-28
GNU Bourne-Again Shell (Bash) Arbitrary Code Execution Vulnerability
GNU

GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute code.

CWE-78 · OS command injection
Refsnvd.nist.gov
Federal remediation due 2022-07-28
CVE-2014-1776
2022-01-28
Microsoft Internet Explorer Memory Corruption Vulnerability
Microsoft

Microsoft Internet Explorer contains a memory corruption vulnerability that allows remote attackers to execute code in the context of the current user.

CWE-416 · Use after free
Refslearn.microsoft.comnvd.nist.gov
Federal remediation due 2022-07-28
CVE-2021-35247
2022-01-21
SolarWinds Serv-U Improper Input Validation Vulnerability
SolarWinds

SolarWinds Serv-U versions 15.2.5 and earlier contain an improper input validation vulnerability that allows attackers to build and send queries without sanitization.

CWE-20 · Improper input validation
Refsnvd.nist.gov
Federal remediation due 2022-02-04
CVE-2018-8453
2022-01-21
Microsoft Win32k Privilege Escalation VulnerabilityRansomware
Microsoft

Microsoft Windows Win32k contains a vulnerability that allows an attacker to escalate privileges.

CWE-404
Refsnvd.nist.gov
Federal remediation due 2022-07-21
CVE-2012-0391
2022-01-21
Apache Struts 2 Improper Input Validation Vulnerability
Apache

The ExceptionDelegator component in Apache Struts 2 before 2.2.3.1 contains an improper input validation vulnerability that allows for remote code execution.

CWE-20 · Improper input validation
Refsnvd.nist.gov
Federal remediation due 2022-07-21
CVE-2006-1547
2022-01-21
Apache Struts 1 ActionForm Denial-of-Service Vulnerability
Apache

ActionForm in Apache Struts versions before 1.2.9 with BeanUtils 1.7 contains a vulnerability that allows for denial-of-service (DoS).

Refsnvd.nist.gov
Federal remediation due 2022-07-21
CVE-2021-40870
2022-01-18
Aviatrix Controller Unrestricted Upload of File
Aviatrix

Unrestricted upload of a file with a dangerous type is possible, which allows an unauthenticated user to execute arbitrary code via directory traversal.

CWE-25CWE-96
Refsnvd.nist.gov
Federal remediation due 2022-02-01
CVE-2021-33766
2022-01-18
Microsoft Exchange Server Information Disclosure
Microsoft

Microsoft Exchange Server contains an information disclosure vulnerability which can allow an unauthenticated attacker to steal email traffic from target.

CWE-287 · Improper authentication
Refsnvd.nist.gov
Federal remediation due 2022-02-01
CVE-2021-32648
2022-01-18
October CMS Improper Authentication
October CMS

In affected versions of the october/system package an attacker can request an account password reset and then gain access to the account using a specially crafted request.

CWE-287 · Improper authentication
Refsnvd.nist.gov
Federal remediation due 2022-02-01
CVE-2021-25298
2022-01-18
Nagios XI OS Command Injection
Nagios

Nagios XI contains a vulnerability which can lead to OS command injection on the Nagios XI server.

CWE-78 · OS command injectionCWE-138
Refsnvd.nist.gov
Federal remediation due 2022-02-01
Prev27 / 34Next