Rosetta Intel
Datasets/KEV CatalogThreat ActorsAttack Surface
Rosetta Lab ↗Blur Horizon LLC
Datasets

KEV Catalog

CISA, queryable

Known exploited vulnerabilities as a queryable table — by CVE, vendor or product.

1685 entries·352 Ransomware·Updated 2026-08-27

1685 results·Page 29 / 34

CVE-2021-41773
2021-11-03
Apache HTTP Server Path Traversal VulnerabilityRansomware
Apache

Apache HTTP Server contains a path traversal vulnerability that allows an attacker to perform remote code execution if files outside directories configured by Alias-like directives are not under default �require all denied� or if CGI scripts are enabled. The original patch issued under this CVE ID is insufficient, please review remediation information under CVE-2021-42013.

CWE-22 · Path traversal
Refsnvd.nist.gov
Federal remediation due 2021-11-17
CVE-2021-40539
2021-11-03
Zoho ManageEngine ADSelfService Plus Authentication Bypass VulnerabilityRansomware
Zoho

Zoho ManageEngine ADSelfService Plus contains an authentication bypass vulnerability affecting the REST API URLs which allow for remote code execution.

CWE-55
Refsnvd.nist.gov
Federal remediation due 2021-11-17
CVE-2021-40444
2021-11-03
Microsoft MSHTML Remote Code Execution VulnerabilityRansomware
Microsoft

Microsoft MSHTML contains a unspecified vulnerability that allows for remote code execution.

CWE-22 · Path traversal
Refsnvd.nist.gov
Federal remediation due 2021-11-17
CVE-2021-38649
2021-11-03
Microsoft Open Management Infrastructure (OMI) Privilege Escalation Vulnerability
Microsoft

Microsoft Open Management Infrastructure (OMI) within Azure VM Management Extensions contains an unspecified vulnerability allowing privilege escalation.

Refsnvd.nist.gov
Federal remediation due 2021-11-17
CVE-2021-38648
2021-11-03
Microsoft Open Management Infrastructure (OMI) Privilege Escalation Vulnerability
Microsoft

Microsoft Open Management Infrastructure (OMI) within Azure VM Management Extensions contains an unspecified vulnerability allowing privilege escalation.

CWE-1390
Refsnvd.nist.gov
Federal remediation due 2021-11-17
CVE-2021-38647
2021-11-03
Microsoft Open Management Infrastructure (OMI) Remote Code Execution VulnerabilityRansomware
Microsoft

Microsoft Open Management Infrastructure (OMI) within Azure VM Management Extensions contains an unspecified vulnerability allowing remote code execution.

CWE-1390
Refsnvd.nist.gov
Federal remediation due 2021-11-17
CVE-2021-38645
2021-11-03
Microsoft Open Management Infrastructure (OMI) Privilege Escalation Vulnerability
Microsoft

Microsoft Open Management Infrastructure (OMI) within Azure VM Management Extensions contains an unspecified vulnerability that allows for privilege escalation.

Refsnvd.nist.gov
Federal remediation due 2021-11-17
CVE-2021-38003
2021-11-03
Google Chromium V8 Memory Corruption Vulnerability
Google

Google Chromium V8 Engine has a bug in JSON.stringify, where the internal TheHole value can leak to script code, causing memory corruption. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

CWE-122 · Heap buffer overflowCWE-755
Refsnvd.nist.gov
Federal remediation due 2021-11-17
CVE-2021-38000
2021-11-03
Google Chromium Intents Improper Input Validation Vulnerability
Google

Google Chromium Intents contains an improper input validation vulnerability that allows a remote attacker to arbitrarily browser to a malicious URL via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

CWE-20 · Improper input validation
Refsnvd.nist.gov
Federal remediation due 2021-11-17
CVE-2021-37976
2021-11-03
Google Chromium Information Disclosure Vulnerability
Google

Google Chromium contains an information disclosure vulnerability within the core memory component that allows a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

CWE-862 · Missing authorization
Refsnvd.nist.gov
Federal remediation due 2021-11-17
CVE-2021-37975
2021-11-03
Google Chromium V8 Use-After-Free Vulnerability
Google

Google Chromium V8 Engine contains a use-after-free vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

CWE-416 · Use after free
Refsnvd.nist.gov
Federal remediation due 2021-11-17
CVE-2021-37973
2021-11-03
Google Chromium Portals Use-After-Free Vulnerability
Google

Google Chromium Portals contains a use-after-free vulnerability that allows a remote attacker, who has compromised the renderer process, to potentially perform a sandbox escape via a crafted HTML page. This vulnerability affects web browsers that utilize Chromium, including Google Chrome and Microsoft Edge.

CWE-416 · Use after free
Refsnvd.nist.gov
Federal remediation due 2021-11-17
CVE-2021-36955
2021-11-03
Microsoft Windows Common Log File System (CLFS) Driver Privilege Escalation VulnerabilityRansomware
Microsoft

Microsoft Windows Common Log File System (CLFS) driver contains an unspecified vulnerability that allows for privilege escalation.

Refsnvd.nist.gov
Federal remediation due 2021-11-17
CVE-2021-36948
2021-11-03
Microsoft Windows Update Medic Service Privilege Escalation Vulnerability
Microsoft

Microsoft Windows Update Medic Service contains an unspecified vulnerability that allows for privilege escalation.

Refsnvd.nist.gov
Federal remediation due 2021-11-17
CVE-2021-36942
2021-11-03
Microsoft Windows Local Security Authority (LSA) Spoofing VulnerabilityRansomware
Microsoft

Microsoft Windows Local Security Authority (LSA) contains a spoofing vulnerability allowing an unauthenticated attacker to call a method on the LSARPC interface and coerce the domain controller to authenticate against another server using NTLM.

CWE-749
Refsnvd.nist.gov
Federal remediation due 2021-11-17
CVE-2021-36742
2021-11-03
Trend Micro Multiple Products Improper Input Validation Vulnerability
Trend Micro / Apex One, Apex One as a Service, and Worry-Free Business Security

Trend Micro Apex One, Apex One as a Service, and Worry-Free Business Security contain an improper input validation vulnerability that allows for privilege escalation.

CWE-20 · Improper input validation
Refssuccess.trendmicro.comnvd.nist.gov
Federal remediation due 2021-11-17
CVE-2021-36741
2021-11-03
Trend Micro Multiple Products Improper Input Validation Vulnerability
Trend Micro / Apex One, Apex One as a Service, and Worry-Free Business Security

Trend Micro Apex One, Apex One as a Service, and Worry-Free Business Security contain an improper input validation vulnerability that allows a remote attacker to upload files.

CWE-22 · Path traversal
Refssuccess.trendmicro.comnvd.nist.gov
Federal remediation due 2021-11-17
CVE-2021-35464
2021-11-03
ForgeRock Access Management (AM) Core Server Remote Code Execution VulnerabilityRansomware
ForgeRock

ForgeRock Access Management (AM) Core Server allows an attacker who sends a specially crafted HTTP request to one of three endpoints (/ccversion/Version, /ccversion/Masthead, or /ccversion/ButtonFrame) to execute code in the context of the current user (unless ForgeRock AM is running as root user, which the vendor does not recommend).

CWE-502 · Deserialization of untrusted data
Refsnvd.nist.gov
Federal remediation due 2021-11-17
CVE-2021-35395
2021-11-03
Realtek AP-Router SDK Buffer Overflow Vulnerability
Realtek

Realtek AP-Router SDK HTTP web server boa contains a buffer overflow vulnerability due to unsafe copies of some overly long parameters submitted in the form that lead to denial-of-service (DoS).

CWE-20 · Improper input validationCWE-122 · Heap buffer overflow
Refsnvd.nist.gov
Federal remediation due 2021-11-17
CVE-2021-35211
2021-11-03
SolarWinds Serv-U Remote Code Execution VulnerabilityRansomware
SolarWinds

SolarWinds Serv-U contains an unspecified memory escape vulnerability which can allow for remote code execution.

CWE-787 · Out-of-bounds write
Refsnvd.nist.gov
Federal remediation due 2021-11-17
CVE-2021-34527
2021-11-03
Microsoft Windows Print Spooler Remote Code Execution VulnerabilityRansomware
Microsoft

Microsoft Windows Print Spooler contains an unspecified vulnerability due to the Windows Print Spooler service improperly performing privileged file operations. Successful exploitation allows an attacker to perform remote code execution with SYSTEM privileges. The vulnerability is also known under the moniker of PrintNightmare.

CWE-269 · Improper privilege management
RefsReference CISA's ED 21-04 (
Federal remediation due 2022-05-03
CVE-2021-34523
2021-11-03
Microsoft Exchange Server Privilege Escalation VulnerabilityRansomware
Microsoft

Microsoft Exchange Server contains an unspecified vulnerability that allows for privilege escalation.

CWE-287 · Improper authentication
Refsnvd.nist.gov
Federal remediation due 2021-11-17
CVE-2021-34473
2021-11-03
Microsoft Exchange Server Remote Code Execution VulnerabilityRansomware
Microsoft

Microsoft Exchange Server contains an unspecified vulnerability that allows for remote code execution.

CWE-918 · Server-side request forgery
Refsnvd.nist.gov
Federal remediation due 2021-11-17
CVE-2021-34448
2021-11-03
Microsoft Windows Scripting Engine Memory Corruption Vulnerability
Microsoft

Microsoft Windows Scripting Engine contains an unspecified vulnerability that allows for memory corruption.

CWE-787 · Out-of-bounds write
Refsnvd.nist.gov
Federal remediation due 2021-11-17
CVE-2021-33771
2021-11-03
Microsoft Windows Kernel Privilege Escalation Vulnerability
Microsoft

Microsoft Windows kernel contains an unspecified vulnerability that allows for privilege escalation.

CWE-119 · Memory buffer bounds
Refsnvd.nist.gov
Federal remediation due 2021-11-17
CVE-2021-33742
2021-11-03
Microsoft Windows MSHTML Platform Remote Code Execution Vulnerability
Microsoft

Microsoft Windows MSHTML Platform contains an unspecified vulnerability that allows for remote code execution.

CWE-787 · Out-of-bounds writeCWE-823
Refsnvd.nist.gov
Federal remediation due 2021-11-17
CVE-2021-33739
2021-11-03
Microsoft Desktop Window Manager (DWM) Core Library Privilege Escalation Vulnerability
Microsoft / Windows

Microsoft Desktop Window Manager (DWM) Core Library contains an unspecified vulnerability that allows for privilege escalation.

Refsnvd.nist.gov
Federal remediation due 2021-11-17
CVE-2021-31979
2021-11-03
Microsoft Windows Kernel Privilege Escalation Vulnerability
Microsoft

Microsoft Windows kernel contains an unspecified vulnerability that allows for privilege escalation.

CWE-119 · Memory buffer bounds
Refsnvd.nist.gov
Federal remediation due 2021-11-17
CVE-2021-31956
2021-11-03
Microsoft Windows NTFS Privilege Escalation Vulnerability
Microsoft

Microsoft Windows New Technology File System (NTFS) contains an unspecified vulnerability that allows attackers to escalate privileges via a specially crafted application.

CWE-191CWE-787 · Out-of-bounds write
Refsnvd.nist.gov
Federal remediation due 2021-11-17
CVE-2021-31955
2021-11-03
Microsoft Windows Kernel Information Disclosure Vulnerability
Microsoft

Microsoft Windows Kernel contains an unspecified vulnerability that allows for information disclosure. Successful exploitation allows attackers to read the contents of kernel memory from a user-mode process.

CWE-497
Refsnvd.nist.gov
Federal remediation due 2021-11-17
CVE-2021-31755
2021-11-03
Tenda AC11 Router Stack Buffer Overflow Vulnerability
Tenda

Tenda AC11 devices contain a stack buffer overflow vulnerability in /goform/setmac which allows attackers to execute code via a crafted post request.

CWE-787 · Out-of-bounds write
Refsnvd.nist.gov
Federal remediation due 2021-11-17
CVE-2021-31207
2021-11-03
Microsoft Exchange Server Security Feature Bypass VulnerabilityRansomware
Microsoft

Microsoft Exchange Server contains an unspecified vulnerability that allows for security feature bypass.

CWE-20 · Improper input validationCWE-434 · Unrestricted file upload
Refsnvd.nist.gov
Federal remediation due 2021-11-17
CVE-2021-31201
2021-11-03
Microsoft Enhanced Cryptographic Provider Privilege Escalation Vulnerability
Microsoft

Microsoft Enhanced Cryptographic Provider contains an unspecified vulnerability that allows for privilege escalation.

Refsnvd.nist.gov
Federal remediation due 2021-11-17
CVE-2021-31199
2021-11-03
Microsoft Enhanced Cryptographic Provider Privilege Escalation Vulnerability
Microsoft

Microsoft Enhanced Cryptographic Provider contains an unspecified vulnerability that allows for privilege escalation.

Refsnvd.nist.gov
Federal remediation due 2021-11-17
CVE-2021-30869
2021-11-03
Apple iOS, iPadOS, and macOS Type Confusion Vulnerability
Apple

Apple iOS, iPadOS, and macOS contain a type confusion vulnerability in the XNU which may allow a malicious application to execute code with kernel privileges.

CWE-843 · Type confusion
Refsnvd.nist.gov
Federal remediation due 2021-11-17
CVE-2021-30860
2021-11-03
Apple Multiple Products Integer Overflow Vulnerability
Apple

Apple iOS, iPadOS, macOS, and watchOS CoreGraphics contain an integer overflow vulnerability which may allow code execution when processing a maliciously crafted PDF. The vulnerability is also known under the moniker of FORCEDENTRY.

CWE-20 · Improper input validationCWE-190 · Integer overflow
Refsnvd.nist.gov
Federal remediation due 2021-11-17
CVE-2021-30858
2021-11-03
Apple iOS, iPadOS, macOS Use-After-Free Vulnerability
Apple / iOS, iPadOS, and macOS

Apple iOS, iPadOS, and macOS WebKit contain a use-after-free vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing.

CWE-416 · Use after free
Refsnvd.nist.gov
Federal remediation due 2021-11-17
CVE-2021-30807
2021-11-03
Apple Multiple Products Memory Corruption Vulnerability
Apple

Apple iOS, iPadOS, macOS, and watchOS IOMobileFrameBuffer contain a memory corruption vulnerability which may allow an application to execute code with kernel privileges.

CWE-787 · Out-of-bounds write
Refsnvd.nist.gov
Federal remediation due 2021-11-17
CVE-2021-30762
2021-11-03
Apple iOS WebKit Use-After-Free Vulnerability
Apple

Apple iOS WebKit contains a use-after-free vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing.

CWE-416 · Use after free
Refsnvd.nist.gov
Federal remediation due 2021-11-17
CVE-2021-30761
2021-11-03
Apple iOS WebKit Memory Corruption Vulnerability
Apple

Apple iOS WebKit contains a memory corruption vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing.

CWE-787 · Out-of-bounds write
Refsnvd.nist.gov
Federal remediation due 2021-11-17
CVE-2021-30713
2021-11-03
Apple macOS Unspecified Vulnerability
Apple

Apple macOS Transparency, Consent, and Control (TCC) contains an unspecified permissions issue which may allow a malicious application to bypass privacy preferences.

CWE-862 · Missing authorization
Refsnvd.nist.gov
Federal remediation due 2021-11-17
CVE-2021-30666
2021-11-03
Apple iOS WebKit Buffer Overflow Vulnerability
Apple

Apple iOS WebKit contains a buffer-overflow vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing.

CWE-119 · Memory buffer bounds
Refsnvd.nist.gov
Federal remediation due 2021-11-17
CVE-2021-30665
2021-11-03
Apple Multiple Products WebKit Memory Corruption Vulnerability
Apple

Apple iOS, iPadOS, macOS, watchOS, and tvOS WebKit contain a memory corruption vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing.

CWE-787 · Out-of-bounds write
Refsnvd.nist.gov
Federal remediation due 2021-11-17
CVE-2021-30663
2021-11-03
Apple Multiple Products WebKit Integer Overflow Vulnerability
Apple

Apple iOS, iPadOS, macOS, tvOS, and Safari WebKit contain an integer overflow vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing.

CWE-20 · Improper input validationCWE-190 · Integer overflow
Refsnvd.nist.gov
Federal remediation due 2021-11-17
CVE-2021-30661
2021-11-03
Apple Multiple Products WebKit Storage Use-After-Free Vulnerability
Apple

Apple iOS, iPadOS, macOS, tvOS, watchOS, and Safari WebKit Storage contain a use-after-free vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing.

CWE-416 · Use after free
Refsnvd.nist.gov
Federal remediation due 2021-11-17
CVE-2021-30657
2021-11-03
Apple macOS Unspecified Vulnerability
Apple

Apple macOS contains an unspecified logic issue in System Preferences that may allow a malicious application to bypass Gatekeeper checks.

CWE-862 · Missing authorization
Refsnvd.nist.gov
Federal remediation due 2021-11-17
CVE-2021-30633
2021-11-03
Google Chromium Indexed DB API Use-After-Free Vulnerability
Google

Google Chromium Indexed DB API contains a use-after-free vulnerability that allows a remote attacker, who has compromised the renderer process, to potentially perform a sandbox escape via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

CWE-416 · Use after free
Refsnvd.nist.gov
Federal remediation due 2021-11-17
CVE-2021-30632
2021-11-03
Google Chromium V8 Out-of-Bounds Write Vulnerability
Google

Google Chromium V8 Engine contains an out-of-bounds write vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

CWE-122 · Heap buffer overflow
Refsnvd.nist.gov
Federal remediation due 2021-11-17
CVE-2021-30563
2021-11-03
Google Chromium V8 Type Confusion Vulnerability
Google

Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

CWE-122 · Heap buffer overflowCWE-843 · Type confusion
Refsnvd.nist.gov
Federal remediation due 2021-11-17
CVE-2021-30554
2021-11-03
Google Chromium WebGL Use-After-Free Vulnerability
Google

Google Chromium WebGL contains a use-after-free vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

CWE-416 · Use after free
Refsnvd.nist.gov
Federal remediation due 2021-11-17
Prev29 / 34Next