Rosetta Intel
Datasets/KEV CatalogThreat ActorsAttack Surface
Rosetta Lab ↗Blur Horizon LLC
Datasets

KEV Catalog

CISA, queryable

Known exploited vulnerabilities as a queryable table — by CVE, vendor or product.

1685 entries·352 Ransomware·Updated 2026-08-27

1685 results·Page 28 / 34

CVE-2021-25297
2022-01-18
Nagios XI OS Command Injection
Nagios

Nagios XI contains a vulnerability which can lead to OS command injection on the Nagios XI server.

CWE-78 · OS command injectionCWE-138
Refsnvd.nist.gov
Federal remediation due 2022-02-01
CVE-2021-25296
2022-01-18
Nagios XI OS Command Injection
Nagios

Nagios XI contains a vulnerability which can lead to OS command injection on the Nagios XI server.

CWE-78 · OS command injectionCWE-138
Refsnvd.nist.gov
Federal remediation due 2022-02-01
CVE-2021-22991
2022-01-18
F5 BIG-IP Traffic Management Microkernel Buffer Overflow
F5

The Traffic Management Microkernel of BIG-IP ASM Risk Engine has a buffer overflow vulnerability, leading to a bypassing of URL-based access controls.

CWE-119 · Memory buffer bounds
Refsnvd.nist.gov
Federal remediation due 2022-02-01
CVE-2021-21975
2022-01-18
VMware Server Side Request Forgery in vRealize Operations Manager APIRansomware
VMware

Server Side Request Forgery (SSRF) in vRealize Operations Manager API prior to 8.4 may allow a malicious actor with network access to the vRealize Operations Manager API to perform a SSRF attack to steal administrative credentials.

CWE-918 · Server-side request forgery
Refsnvd.nist.gov
Federal remediation due 2022-02-01
CVE-2021-21315
2022-01-18
System Information Library for Node.JS Command Injection
Npm package

In this vulnerability, an attacker can send a malicious payload that will exploit the name parameter. After successful exploitation, attackers can execute remote.

CWE-78 · OS command injection
Refsnvd.nist.gov
Federal remediation due 2022-02-01
CVE-2020-14864
2022-01-18
Oracle Business Intelligence Enterprise Edition Path Transversal
Oracle

Path traversal vulnerability, where an attacker can target the preview FilePath parameter of the getPreviewImage function to get access to arbitrary system file.

CWE-22 · Path traversal
Refsnvd.nist.gov
Federal remediation due 2022-07-18
CVE-2020-13927
2022-01-18
Apache Airflow's Experimental API Authentication Bypass
Apache

The previous default setting for Airflow's Experimental API was to allow all API requests without authentication.

CWE-1188CWE-306 · Missing authentication
Refsnvd.nist.gov
Federal remediation due 2022-07-18
CVE-2020-13671
2022-01-18
Drupal core Un-restricted Upload of File
Drupal

Improper sanitization in the extension file names is present in Drupal core.

CWE-434 · Unrestricted file upload
Refsnvd.nist.gov
Federal remediation due 2022-07-18
CVE-2020-11978
2022-01-18
Apache Airflow Command Injection
Apache

A remote code/command injection vulnerability was discovered in one of the example DAGs shipped with Airflow.

CWE-78 · OS command injection
Refsnvd.nist.gov
Federal remediation due 2022-07-18
CVE-2021-36260
2022-01-10
Hikvision Improper Input Validation
Hikvision / Security cameras web server

A command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation.

CWE-78 · OS command injection
Refsnvd.nist.gov
Federal remediation due 2022-01-24
CVE-2021-27860
2022-01-10
FatPipe WARP, IPVPN, and MPVPN Configuration Upload exploit
FatPipe / WARP, IPVPN, and MPVPN software

A vulnerability in the web management interface of FatPipe WARP, IPVPN, and MPVPN software allows a remote, unauthenticated attacker to upload a file to any location on the filesystem.

CWE-434 · Unrestricted file upload
Refsnvd.nist.gov
Federal remediation due 2022-01-24
CVE-2021-22017
2022-01-10
VMware vCenter Server Improper Access Control
VMware

Rhttproxy as used in vCenter Server contains a vulnerability due to improper implementation of URI normalization.

CWE-23 · Relative path traversal
Refsnvd.nist.gov
Federal remediation due 2022-01-24
CVE-2020-6572
2022-01-10
Google Chrome Media Use-After-Free Vulnerability
Google

Google Chrome Media contains a use-after-free vulnerability that allows a remote attacker to execute code via a crafted HTML page.

CWE-416 · Use after free
Refsnvd.nist.gov
Federal remediation due 2022-07-10
CVE-2019-9670
2022-01-10
Synacor Zimbra Collaboration Suite (ZCS) Improper Restriction of XML External Entity Reference
Synacor

Synacor Zimbra Collaboration Suite (ZCS) contains an improper restriction of XML external entity (XXE) vulnerability in the mailboxd component.

CWE-611
Refsnvd.nist.gov
Federal remediation due 2022-07-10
CVE-2019-7609
2022-01-10
Kibana Arbitrary Code Execution
Elastic

Kibana contain an arbitrary code execution flaw in the Timelion visualizer.

CWE-94 · Code injection
Refsnvd.nist.gov
Federal remediation due 2022-07-10
CVE-2019-2725
2022-01-10
Oracle WebLogic Server, InjectionRansomware
Oracle

Injection vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services).

CWE-74
Refsnvd.nist.gov
Federal remediation due 2022-07-10
CVE-2019-1579
2022-01-10
Palo Alto Networks PAN-OS Remote Code Execution VulnerabilityRansomware
Palo Alto Networks

Remote Code Execution in PAN-OS with GlobalProtect Portal or GlobalProtect Gateway Interface enabled.

CWE-134
Refsnvd.nist.gov
Federal remediation due 2022-07-10
CVE-2019-1458
2022-01-10
Microsoft Win32k Privilege Escalation VulnerabilityRansomware
Microsoft

A privilege escalation vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k EoP.

Refsnvd.nist.gov
Federal remediation due 2022-07-10
CVE-2019-10149
2022-01-10
Exim Mail Transfer Agent (MTA) Improper Input Validation
Exim

Improper validation of recipient address in deliver_message() function in /src/deliver.c may lead to remote command execution.

CWE-78 · OS command injection
Refsnvd.nist.gov
Federal remediation due 2022-07-10
CVE-2018-13383
2022-01-10
Fortinet FortiOS and FortiProxy Out-of-bounds WriteRansomware
Fortinet

A heap buffer overflow in Fortinet FortiOS and FortiProxy may cause the SSL VPN web service termination for logged in users.

CWE-787 · Out-of-bounds write
Refsnvd.nist.gov
Federal remediation due 2022-07-10
CVE-2018-13382
2022-01-10
Fortinet FortiOS and FortiProxy Improper AuthorizationRansomware
Fortinet

An Improper Authorization vulnerability in Fortinet FortiOS and FortiProxy under SSL VPN web portal allows an unauthenticated attacker to modify the password.

CWE-285
Refsnvd.nist.gov
Federal remediation due 2022-07-10
CVE-2017-1000486
2022-01-10
Primetek Primefaces Remote Code Execution Vulnerability
Primetek / Primefaces Application

Primetek Primefaces is vulnerable to a weak encryption flaw resulting in remote code execution

CWE-326
Refsnvd.nist.gov
Federal remediation due 2022-07-10
CVE-2015-7450
2022-01-10
IBM WebSphere Application Server and Server Hypervisor Edition Code Injection.
IBM

Serialized-object interfaces in certain IBM analytics, business solutions, cognitive, IT infrastructure, and mobile and social products allow remote attackers to execute arbitrary commands

CWE-94 · Code injection
Refsnvd.nist.gov
Federal remediation due 2022-07-10
CVE-2013-3900
2022-01-10
Microsoft WinVerifyTrust function Remote Code Execution
Microsoft

A remote code execution vulnerability exists in the way that the WinVerifyTrust function handles Windows Authenticode signature verification for PE files.

CWE-20 · Improper input validation
Refsnvd.nist.gov
Federal remediation due 2022-07-10
CVE-2021-43890
2021-12-15
Microsoft Windows AppX Installer Spoofing VulnerabilityRansomware
Microsoft

Microsoft Windows AppX Installer contains a spoofing vulnerability which has a high impacts to confidentiality, integrity, and availability.

Refsnvd.nist.gov
Federal remediation due 2021-12-29
CVE-2021-4102
2021-12-15
Google Chromium V8 Use-After-Free Vulnerability
Google

Google Chromium V8 Engine contains a use-after-free vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

CWE-416 · Use after free
Refsnvd.nist.gov
Federal remediation due 2021-12-29
CVE-2021-44515
2021-12-10
Zoho Desktop Central Authentication Bypass Vulnerability
Zoho

Zoho Desktop Central contains an authentication bypass vulnerability that could allow an attacker to execute arbitrary code in the Desktop Central MSP server.

Refsnvd.nist.gov
Federal remediation due 2021-12-24
CVE-2021-44228
2021-12-10
Apache Log4j2 Remote Code Execution VulnerabilityRansomware
Apache

Apache Log4j2 contains a vulnerability where JNDI features do not protect against attacker-controlled JNDI-related endpoints, allowing for remote code execution.

CWE-20 · Improper input validationCWE-400CWE-502 · Deserialization of untrusted data
Refsnvd.nist.gov
Federal remediation due 2021-12-24
CVE-2021-44168
2021-12-10
Fortinet FortiOS Arbitrary File Download
Fortinet

Fortinet FortiOS "execute restore src-vis" downloads code without integrity checking, allowing an attacker to arbitrarily download files.

CWE-494
Refsnvd.nist.gov
Federal remediation due 2021-12-24
CVE-2021-35394
2021-12-10
Realtek Jungle SDK Remote Code Execution Vulnerability
Realtek / Jungle Software Development Kit (SDK)

RealTek Jungle SDK contains multiple memory corruption vulnerabilities which can allow an attacker to perform remote code execution.

CWE-78 · OS command injectionCWE-138
Refsnvd.nist.gov
Federal remediation due 2021-12-24
CVE-2020-8816
2021-12-10
Pi-Hole AdminLTE Remote Code Execution Vulnerability
Pi-hole

Pi-hole Web v4.3.2 (aka AdminLTE) allows Remote Code Execution by privileged dashboard users via a crafted DHCP static lease.

CWE-78 · OS command injection
Refsnvd.nist.gov
Federal remediation due 2022-06-10
CVE-2020-17463
2021-12-10
Fuel CMS SQL Injection Vulnerability
Fuel CMS

FUEL CMS 1.4.7 allows SQL Injection via the col parameter to /pages/items, /permissions/items, or /navigation/items.

CWE-89 · SQL injection
Refsnvd.nist.gov
Federal remediation due 2022-06-10
CVE-2019-7238
2021-12-10
Sonatype Nexus Repository Manager Incorrect Access Control Vulnerability
Sonatype

Sonatype Nexus Repository Manager before 3.15.0 has an incorrect access control vulnerability. Exploitation allows for remote code execution.

Refsnvd.nist.gov
Federal remediation due 2022-06-10
CVE-2019-13272
2021-12-10
Linux Kernel Improper Privilege Management Vulnerability
Linux

Kernel/ptrace.c in Linux kernel mishandles contains an improper privilege management vulnerability that allows local users to obtain root access.

CWE-269 · Improper privilege management
Refsnvd.nist.gov
Federal remediation due 2022-06-10
CVE-2019-10758
2021-12-10
MongoDB mongo-express Remote Code Execution Vulnerability
MongoDB

mongo-express before 0.54.0 is vulnerable to Remote Code Execution via endpoints that uses the `toBSON` method.

Refsnvd.nist.gov
Federal remediation due 2022-06-10
CVE-2019-0193
2021-12-10
Apache Solr DataImportHandler Code Injection Vulnerability
Apache

The optional Apache Solr module DataImportHandler contains a code injection vulnerability.

CWE-94 · Code injection
Refsnvd.nist.gov
Federal remediation due 2022-06-10
CVE-2017-17562
2021-12-10
Embedthis GoAhead Remote Code Execution Vulnerability
Embedthis

Embedthis GoAhead before 3.6.5 allows remote code execution if CGI is enabled and a CGI program is dynamically linked.

CWE-20 · Improper input validation
Refsnvd.nist.gov
Federal remediation due 2022-06-10
CVE-2017-12149
2021-12-10
Red Hat JBoss Application Server Remote Code Execution VulnerabilityRansomware
Red Hat

The JBoss Application Server, shipped with Red Hat Enterprise Application Platform 5.2, allows an attacker to execute arbitrary code via crafted serialized data.

CWE-502 · Deserialization of untrusted data
Refsnvd.nist.gov
Federal remediation due 2022-06-10
CVE-2010-1871
2021-12-10
Red Hat Linux JBoss Seam 2 Remote Code Execution Vulnerability
Red Hat

JBoss Seam 2 (jboss-seam2), as used in JBoss Enterprise Application Platform 4.3.0 for Red Hat Linux, allows attackers to perform remote code execution. This vulnerability can only be exploited when the Java Security Manager is not properly configured.

CWE-20 · Improper input validation
Refsnvd.nist.gov
Federal remediation due 2022-06-10
CVE-2021-44077
2021-12-01
Zoho ManageEngine ServiceDesk Plus Remote Code Execution Vulnerability
Zoho / ManageEngine ServiceDesk Plus (SDP) / SupportCenter Plus

Zoho ManageEngine ServiceDesk Plus before 11306, ServiceDesk Plus MSP before 10530, and SupportCenter Plus before 11014 are vulnerable to unauthenticated remote code execution

CWE-306 · Missing authentication
Refsnvd.nist.gov
Federal remediation due 2021-12-15
CVE-2021-40438
2021-12-01
Apache HTTP Server-Side Request Forgery (SSRF)Ransomware
Apache

A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. This issue affects Apache HTTP Server 2.4.48 and earlier.

CWE-918 · Server-side request forgery
Refsnvd.nist.gov
Federal remediation due 2021-12-15
CVE-2021-37415
2021-12-01
Zoho ManageEngine ServiceDesk Authentication Bypass Vulnerability
Zoho / ManageEngine ServiceDesk Plus (SDP)

Zoho ManageEngine ServiceDesk Plus before 11302 is vulnerable to authentication bypass that allows a few REST-API URLs without authentication

CWE-306 · Missing authentication
Refsnvd.nist.gov
Federal remediation due 2021-12-15
CVE-2020-11261
2021-12-01
Qualcomm Multiple Chipsets Improper Input Validation Vulnerability
Qualcomm / Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables

Memory corruption due to improper check to return error when user application requests memory allocation of a huge size in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables

CWE-20 · Improper input validation
Refsnvd.nist.gov
Federal remediation due 2022-06-01
CVE-2018-14847
2021-12-01
MikroTik Router OS Directory Traversal Vulnerability
MikroTik / RouterOS

MikroTik RouterOS through 6.42 allows unauthenticated remote attackers to read arbitrary files and remote authenticated attackers to write arbitrary files due to a directory traversal vulnerability in the WinBox interface.

CWE-22 · Path traversal
Refsnvd.nist.gov
Federal remediation due 2022-06-01
CVE-2021-42321
2021-11-17
Microsoft Exchange Server Remote Code Execution VulnerabilityRansomware
Microsoft

An authenticated attacker could leverage improper validation in cmdlet arguments within Microsoft Exchange and perform remote code execution.

CWE-184CWE-502 · Deserialization of untrusted data
Refsnvd.nist.gov
Federal remediation due 2021-12-01
CVE-2021-42292
2021-11-17
Microsoft Excel Security Feature Bypass
Microsoft / Office

A security feature bypass vulnerability in Microsoft Excel would allow a local user to perform arbitrary code execution.

CWE-357
Refsnvd.nist.gov
Federal remediation due 2021-12-01
CVE-2021-40449
2021-11-17
Microsoft Windows Win32k Privilege Escalation VulnerabilityRansomware
Microsoft

Unspecified vulnerability allows for an authenticated user to escalate privileges.

CWE-416 · Use after free
Refsnvd.nist.gov
Federal remediation due 2021-12-01
CVE-2021-22204
2021-11-17
ExifTool Remote Code Execution Vulnerability
Perl

Improper neutralization of user data in the DjVu file format in Exiftool versions 7.44 and up allows arbitrary code execution when parsing the malicious image

CWE-95
Refsnvd.nist.gov
Federal remediation due 2021-12-01
CVE-2021-42258
2021-11-03
BQE BillQuick Web Suite SQL Injection VulnerabilityRansomware
BQE

BQE BillQuick Web Suite contains an SQL injection vulnerability when accessing the username parameter that may allow for unauthenticated, remote code execution.

CWE-89 · SQL injection
Refsnvd.nist.gov
Federal remediation due 2021-11-17
CVE-2021-42013
2021-11-03
Apache HTTP Server Path Traversal VulnerabilityRansomware
Apache

Apache HTTP Server contains a path traversal vulnerability that allows an attacker to perform remote code execution if files outside directories configured by Alias-like directives are not under default require all denied or if CGI scripts are enabled. This CVE ID resolves an incomplete patch for CVE-2021-41773.

CWE-22 · Path traversal
Refsnvd.nist.gov
Federal remediation due 2021-11-17
Prev28 / 34Next