Rosetta Intel
Datasets/KEV CatalogThreat ActorsAttack Surface
Rosetta Lab ↗Blur Horizon LLC
Datasets

KEV Catalog

CISA, queryable

Known exploited vulnerabilities as a queryable table — by CVE, vendor or product.

1685 entries·352 Ransomware·Updated 2026-08-27

1685 results·Page 30 / 34

CVE-2021-30551
2021-11-03
Google Chromium V8 Type Confusion Vulnerability
Google

Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

CWE-122 · Heap buffer overflowCWE-843 · Type confusion
Refsnvd.nist.gov
Federal remediation due 2021-11-17
CVE-2021-30116
2021-11-03
Kaseya Virtual System/Server Administrator (VSA) Information Disclosure VulnerabilityRansomware
Kaseya

Kaseya Virtual System/Server Administrator (VSA) contains an information disclosure vulnerability allowing an attacker to obtain the sessionId that can be used to execute further attacks against the system.

CWE-522
Refsnvd.nist.gov
Federal remediation due 2021-11-17
CVE-2021-28664
2021-11-03
Arm Mali Graphics Processing Unit (GPU) Unspecified Vulnerability
Arm

Arm Mali Graphics Processing Unit (GPU) kernel driver contains an unspecified vulnerability that may allow a non-privileged user to gain write access to read-only memory, gain root privilege, corrupt memory, and modify the memory of other processes.

CWE-787 · Out-of-bounds write
Refsnvd.nist.gov
Federal remediation due 2021-11-17
CVE-2021-28663
2021-11-03
Arm Mali Graphics Processing Unit (GPU) Use-After-Free Vulnerability
Arm

Arm Mali Graphics Processing Unit (GPU) kernel driver contains a use-after-free vulnerability that may allow a non-privileged user to make improper operations on GPU memory to gain root privilege, and/or disclose information.

CWE-416 · Use after free
Refsnvd.nist.gov
Federal remediation due 2021-11-17
CVE-2021-28550
2021-11-03
Adobe Acrobat and Reader Use-After-Free Vulnerability
Adobe

Adobe Acrobat and Reader contains a use-after-free vulnerability that could allow an unauthenticated attacker to achieve code execution in the context of the current user.

CWE-416 · Use after free
Refsnvd.nist.gov
Federal remediation due 2021-11-17
CVE-2021-28310
2021-11-03
Microsoft Win32k Privilege Escalation Vulnerability
Microsoft

Microsoft Windows Win32k contains an unspecified vulnerability that allows for privilege escalation.

CWE-787 · Out-of-bounds write
Refsnvd.nist.gov
Federal remediation due 2021-11-17
CVE-2021-27562
2021-11-03
Arm Trusted Firmware Out-of-Bounds Write Vulnerability
Arm

Arm Trusted Firmware contains an out-of-bounds write vulnerability allowing the non-secure (NS) world to trigger a system halt, overwrite secure data, or print out secure data when calling secure functions under the non-secure processing environment (NSPE) handler mode. This vulnerability affects Yealink Device Management servers.

CWE-787 · Out-of-bounds write
Refsnvd.nist.gov
Federal remediation due 2021-11-17
CVE-2021-27561
2021-11-03
Yealink Device Management Server-Side Request Forgery (SSRF) Vulnerability
Yealink

Yealink Device Management contains a server-side request forgery (SSRF) vulnerability that allows for unauthenticated remote code execution.

CWE-78 · OS command injection
Refsnvd.nist.gov
Federal remediation due 2021-11-17
CVE-2021-27104
2021-11-03
Accellion FTA OS Command Injection VulnerabilityRansomware
Accellion

Accellion FTA contains an OS command injection vulnerability exploited via a crafted POST request to various admin endpoints.

CWE-20 · Improper input validationCWE-78 · OS command injection
Refsnvd.nist.gov
Federal remediation due 2021-11-17
CVE-2021-27103
2021-11-03
Accellion FTA Server-Side Request Forgery (SSRF) VulnerabilityRansomware
Accellion

Accellion FTA contains a server-side request forgery (SSRF) vulnerability exploited via a crafted POST request to wmProgressstat.html.

CWE-918 · Server-side request forgery
Refsnvd.nist.gov
Federal remediation due 2021-11-17
CVE-2021-27102
2021-11-03
Accellion FTA OS Command Injection VulnerabilityRansomware
Accellion

Accellion FTA contains an OS command injection vulnerability exploited via a local web service call.

CWE-20 · Improper input validationCWE-78 · OS command injection
Refsnvd.nist.gov
Federal remediation due 2021-11-17
CVE-2021-27101
2021-11-03
Accellion FTA SQL Injection VulnerabilityRansomware
Accellion

Accellion FTA contains a SQL injection vulnerability exploited via a crafted host header in a request to document_root.html.

CWE-89 · SQL injectionCWE-138
Refsnvd.nist.gov
Federal remediation due 2021-11-17
CVE-2021-27085
2021-11-03
Microsoft Internet Explorer Remote Code Execution Vulnerability
Microsoft

Microsoft Internet Explorer contains an unspecified vulnerability that allows for remote code execution.

Refsnvd.nist.gov
Federal remediation due 2021-11-17
CVE-2021-27065
2021-11-03
Microsoft Exchange Server Remote Code Execution VulnerabilityRansomware
Microsoft

Microsoft Exchange Server contains an unspecified vulnerability that allows for remote code execution. This vulnerability is part of the ProxyLogon exploit chain.

CWE-39
RefsReference CISA's ED 21-02 (
Federal remediation due 2022-05-03
CVE-2021-27059
2021-11-03
Microsoft Office Remote Code Execution Vulnerability
Microsoft

Microsoft Office contains an unspecified vulnerability that allows for remote code execution.

Refsnvd.nist.gov
Federal remediation due 2021-11-17
CVE-2021-26858
2021-11-03
Microsoft Exchange Server Remote Code Execution VulnerabilityRansomware
Microsoft

Microsoft Exchange Server contains an unspecified vulnerability that allows for remote code execution. This vulnerability is part of the ProxyLogon exploit chain.

RefsReference CISA's ED 21-02 (
Federal remediation due 2022-05-03
CVE-2021-26857
2021-11-03
Microsoft Exchange Server Remote Code Execution VulnerabilityRansomware
Microsoft

Microsoft Exchange Server contains an unspecified vulnerability that allows for remote code execution. This vulnerability is part of the ProxyLogon exploit chain.

CWE-502 · Deserialization of untrusted data
RefsReference CISA's ED 21-02 (
Federal remediation due 2022-05-03
CVE-2021-26855
2021-11-03
Microsoft Exchange Server Remote Code Execution VulnerabilityRansomware
Microsoft

Microsoft Exchange Server contains an unspecified vulnerability that allows for remote code execution. This vulnerability is part of the ProxyLogon exploit chain.

CWE-918 · Server-side request forgery
RefsReference CISA's ED 21-02 (
Federal remediation due 2022-05-03
CVE-2021-26411
2021-11-03
Microsoft Internet Explorer Memory Corruption VulnerabilityRansomware
Microsoft

Microsoft Internet Explorer contains an unspecified vulnerability that allows for memory corruption.

CWE-416 · Use after free
Refsnvd.nist.gov
Federal remediation due 2021-11-17
CVE-2021-26084
2021-11-03
Atlassian Confluence Server and Data Center Object-Graph Navigation Language (OGNL) Injection VulnerabilityRansomware
Atlassian

Atlassian Confluence Server and Data Server contain an Object-Graph Navigation Language (OGNL) injection vulnerability that may allow an unauthenticated attacker to execute code.

CWE-917
Refsnvd.nist.gov
Federal remediation due 2021-11-17
CVE-2021-23874
2021-11-03
McAfee Total Protection (MTP) Improper Privilege Management Vulnerability
McAfee

McAfee Total Protection (MTP) contains an improper privilege management vulnerability that allows a local user to gain elevated privileges and execute code, bypassing MTP self-defense.

CWE-284 · Improper access control
Refsnvd.nist.gov
Federal remediation due 2021-11-17
CVE-2021-22986
2021-11-03
F5 BIG-IP and BIG-IQ Centralized Management iControl REST Remote Code Execution VulnerabilityRansomware
F5

F5 BIG-IP and BIG-IQ Centralized Management contain a remote code execution vulnerability in the iControl REST interface that allows unauthenticated attackers with network access to execute system commands, create or delete files, and disable services.

CWE-863
Refsnvd.nist.gov
Federal remediation due 2021-11-17
CVE-2021-22900
2021-11-03
Ivanti Pulse Connect Secure Unrestricted File Upload Vulnerability
Ivanti

Ivanti Pulse Connect Secure contains an unrestricted file upload vulnerability that allows an authenticated administrator to perform a file write via a maliciously crafted archive upload in the administrator web interface.

CWE-94 · Code injection
RefsReference CISA's ED 21-03 (
Federal remediation due 2022-05-03
CVE-2021-22899
2021-11-03
Ivanti Pulse Connect Secure Command Injection Vulnerability
Ivanti

Ivanti Pulse Connect Secure contains a command injection vulnerability that allows remote authenticated users to perform remote code execution via Windows File Resource Profiles.

CWE-77 · Command injection
RefsReference CISA's ED 21-03 (
Federal remediation due 2022-05-03
CVE-2021-22894
2021-11-03
Ivanti Pulse Connect Secure Collaboration Suite Buffer Overflow Vulnerability
Ivanti

Ivanti Pulse Connect Secure Collaboration Suite contains a buffer overflow vulnerabilities that allows a remote authenticated users to execute code as the root user via maliciously crafted meeting room.

CWE-94 · Code injection
RefsReference CISA's ED 21-03 (
Federal remediation due 2022-05-03
CVE-2021-22893
2021-11-03
Ivanti Pulse Connect Secure Use-After-Free VulnerabilityRansomware
Ivanti

Ivanti Pulse Connect Secure contains a use-after-free vulnerability that allow a remote, unauthenticated attacker to execute code via license services.

CWE-287 · Improper authentication
RefsReference CISA's ED 21-03 (
Federal remediation due 2022-05-03
CVE-2021-22506
2021-11-03
Micro Focus Access Manager Information Leakage Vulnerability
Micro Focus

Micro Focus Access Manager contains an information leakage vulnerability resulting from a SAML service provider redirection issue when the Assertion Consumer Service URL is used.

Refsnvd.nist.gov
Federal remediation due 2021-11-17
CVE-2021-22502
2021-11-03
Micro Focus Operation Bridge Report (OBR) Remote Code Execution Vulnerability
Micro Focus / Operation Bridge Reporter (OBR)

Micro Focus Operation Bridge Report (OBR) contains an unspecified vulnerability that allows for remote code execution.

CWE-20 · Improper input validationCWE-78 · OS command injection
Refsnvd.nist.gov
Federal remediation due 2021-11-17
CVE-2021-22205
2021-11-03
GitLab Community and Enterprise Editions Remote Code Execution VulnerabilityRansomware
GitLab

GitHub Community and Enterprise Editions that utilize the ability to upload images through GitLab Workhorse are vulnerable to remote code execution. Workhorse passes image file extensions through ExifTool, which improperly validates the image files.

CWE-20 · Improper input validationCWE-95
Refsnvd.nist.gov
Federal remediation due 2021-11-17
CVE-2021-22005
2021-11-03
VMware vCenter Server File Upload VulnerabilityRansomware
VMware

VMware vCenter Server contains a file upload vulnerability in the Analytics service that allows a user with network access to port 443 to execute code.

CWE-23 · Relative path traversal
Refsnvd.nist.gov
Federal remediation due 2021-11-17
CVE-2021-21985
2021-11-03
VMware vCenter Server Improper Input Validation VulnerabilityRansomware
VMware

VMware vSphere Client contains an improper input validation vulnerability in the Virtual SAN Health Check plug-in, which is enabled by default in vCenter Server, which allows for remote code execution.

CWE-20 · Improper input validationCWE-470CWE-918 · Server-side request forgery
Refsnvd.nist.gov
Federal remediation due 2021-11-17
CVE-2021-21972
2021-11-03
VMware vCenter Server Remote Code Execution VulnerabilityRansomware
VMware

VMware vCenter Server vSphere Client contains a remote code execution vulnerability in a vCenter Server plugin which allows an attacker with network access to port 443 to execute commands with unrestricted privileges on the underlying operating system.

CWE-23 · Relative path traversal
Refsnvd.nist.gov
Federal remediation due 2021-11-17
CVE-2021-21224
2021-11-03
Google Chromium V8 Type Confusion Vulnerability
Google

Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to execute code inside a sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

CWE-843 · Type confusion
Refsnvd.nist.gov
Federal remediation due 2021-11-17
CVE-2021-21220
2021-11-03
Google Chromium V8 Improper Input Validation Vulnerability
Google

Google Chromium V8 Engine contains an improper input validation vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

CWE-20 · Improper input validationCWE-122 · Heap buffer overflow
Refsnvd.nist.gov
Federal remediation due 2021-11-17
CVE-2021-21206
2021-11-03
Google Chromium Blink Use-After-Free Vulnerability
Google

Google Chromium Blink contains a use-after-free vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

CWE-416 · Use after free
Refsnvd.nist.gov
Federal remediation due 2021-11-17
CVE-2021-21193
2021-11-03
Google Chromium Blink Use-After-Free Vulnerability
Google

Google Chromium Blink contains a use-after-free vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

CWE-416 · Use after free
Refsnvd.nist.gov
Federal remediation due 2021-11-17
CVE-2021-21166
2021-11-03
Google Chromium Race Condition Vulnerability
Google

Google Chromium contains a race condition vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

CWE-122 · Heap buffer overflowCWE-362
Refsnvd.nist.gov
Federal remediation due 2021-11-17
CVE-2021-21148
2021-11-03
Google Chromium V8 Heap Buffer Overflow Vulnerability
Google

Google Chromium V8 Engine contains a heap buffer overflow vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

CWE-122 · Heap buffer overflow
Refsnvd.nist.gov
Federal remediation due 2021-11-17
CVE-2021-21017
2021-11-03
Adobe Acrobat and Reader Heap-based Buffer Overflow Vulnerability
Adobe

Acrobat Acrobat and Reader contain a heap-based buffer overflow vulnerability that could allow an unauthenticated attacker to achieve code execution in the context of the current user.

CWE-122 · Heap buffer overflow
Refsnvd.nist.gov
Federal remediation due 2021-11-17
CVE-2021-20090
2021-11-03
Arcadyan Buffalo Firmware Path Traversal Vulnerability
Arcadyan

Arcadyan Buffalo firmware contains a path traversal vulnerability that could allow unauthenticated, remote attackers to bypass authentication and access sensitive information. This vulnerability affects multiple routers across several different vendors.

CWE-22 · Path traversal
Refsnvd.nist.gov
Federal remediation due 2021-11-17
CVE-2021-20023
2021-11-03
SonicWall Email Security Path Traversal VulnerabilityRansomware
SonicWall

SonicWall Email Security contains a path traversal vulnerability that allows a post-authenticated attacker to read files on the remote host. This vulnerability has known usage in a SonicWall Email Security exploit chain along with CVE-2021-20021 and CVE-2021-20022 to achieve privilege escalation.

CWE-22 · Path traversal
Refsnvd.nist.gov
Federal remediation due 2021-11-17
CVE-2021-20022
2021-11-03
SonicWall Email Security Unrestricted Upload of File VulnerabilityRansomware
SonicWall

SonicWall Email Security contains an unrestricted upload of file with dangerous type vulnerability that allows a post-authenticated attacker to upload a file to the remote host. This vulnerability has known usage in a SonicWall Email Security exploit chain along with CVE-2021-20021 and CVE-2021-20023 to achieve privilege escalation.

CWE-434 · Unrestricted file upload
Refsnvd.nist.gov
Federal remediation due 2021-11-17
CVE-2021-20021
2021-11-03
SonicWall Email Security Improper Privilege Management VulnerabilityRansomware
SonicWall

SonicWall Email Security contains an improper privilege management vulnerability that allows an attacker to create an administrative account by sending a crafted HTTP request to the remote host. This vulnerability has known usage in a SonicWall Email Security exploit chain along with CVE-2021-20022 and CVE-2021-20023 to achieve privilege escalation.

CWE-306 · Missing authentication
Refsnvd.nist.gov
Federal remediation due 2021-11-17
CVE-2021-20016
2021-11-03
SonicWall SSLVPN SMA100 SQL Injection VulnerabilityRansomware
SonicWall

SonicWall SSLVPN SMA100 contains a SQL injection vulnerability that allows remote exploitation for credential access by an unauthenticated attacker.

CWE-89 · SQL injection
Refsnvd.nist.gov
Federal remediation due 2021-11-17
CVE-2021-1906
2021-11-03
Qualcomm Multiple Chipsets Detection of Error Condition Without Action Vulnerability
Qualcomm

Multiple Qualcomm chipsets contain a detection of error condition without action vulnerability when improper handling of address deregistration on failure can lead to new GPU address allocation failure.

CWE-390
Refsnvd.nist.gov
Federal remediation due 2021-11-17
CVE-2021-1905
2021-11-03
Qualcomm Multiple Chipsets Use-After-Free Vulnerability
Qualcomm

Multiple Qualcomm Chipsets contain a use after free vulnerability due to improper handling of memory mapping of multiple processes simultaneously.

CWE-416 · Use after free
Refsnvd.nist.gov
Federal remediation due 2022-05-03
CVE-2021-1879
2021-11-03
Apple iOS, iPadOS, and watchOS WebKit Cross-Site Scripting (XSS) Vulnerability
Apple

Apple iOS, iPadOS, and watchOS WebKit contain an unspecified vulnerability that allows for universal cross-site scripting (XSS) when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing.

CWE-79 · Cross-site scripting
Refsnvd.nist.gov
Federal remediation due 2021-11-17
CVE-2021-1871
2021-11-03
Apple iOS, iPadOS, and macOS WebKit Remote Code Execution Vulnerability
Apple

Apple iOS, iPadOS, and macOS WebKit contain an unspecified logic vulnerability that allows a remote attacker to execute code. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing.

CWE-1173
Refsnvd.nist.gov
Federal remediation due 2021-11-17
CVE-2021-1870
2021-11-03
Apple iOS, iPadOS, and macOS WebKit Remote Code Execution Vulnerability
Apple

Apple iOS, iPadOS, and macOS WebKit contain an unspecified logic vulnerability that allows a remote attacker to execute code. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing.

CWE-1173
Refsnvd.nist.gov
Federal remediation due 2021-11-17
CVE-2021-1782
2021-11-03
Apple Multiple Products Race Condition Vulnerability
Apple

Apple iOS, iPadOs, macOS, watchOS, and tvOS contain a race condition vulnerability that may allow a malicious application to elevate privileges.

CWE-362CWE-667
Refsnvd.nist.gov
Federal remediation due 2021-11-17
Prev30 / 34Next