Rosetta Intel
Datasets/KEV CatalogThreat ActorsAttack Surface
Rosetta Lab ↗Blur Horizon LLC
Datasets

KEV Catalog

CISA, queryable

Known exploited vulnerabilities as a queryable table — by CVE, vendor or product.

1685 entries·352 Ransomware·Updated 2026-08-27

1685 results·Page 31 / 34

CVE-2021-1732
2021-11-03
Microsoft Win32k Privilege Escalation VulnerabilityRansomware
Microsoft

Microsoft Win32k contains an unspecified vulnerability that allows for privilege escalation.

CWE-787 · Out-of-bounds write
Refsnvd.nist.gov
Federal remediation due 2021-11-17
CVE-2021-1675
2021-11-03
Microsoft Windows Print Spooler Remote Code Execution VulnerabilityRansomware
Microsoft

Microsoft Windows Print Spooler contains an unspecified vulnerability that allows for remote code execution.

CWE-285
Refsnvd.nist.gov
Federal remediation due 2021-11-17
CVE-2021-1647
2021-11-03
Microsoft Defender Remote Code Execution Vulnerability
Microsoft

Microsoft Defender contains an unspecified vulnerability that allows for remote code execution.

CWE-122 · Heap buffer overflowCWE-1285
Refsnvd.nist.gov
Federal remediation due 2021-11-17
CVE-2021-1498
2021-11-03
Cisco HyperFlex HX Data Platform Command Injection Vulnerability
Cisco

Cisco HyperFlex HX Installer Virtual Machine contains an insufficient input validation vulnerability which could allow an attacker to execute commands on an affected device as the tomcat8 user.

CWE-78 · OS command injection
Refsnvd.nist.gov
Federal remediation due 2021-11-17
CVE-2021-1497
2021-11-03
Cisco HyperFlex HX Installer Virtual Machine Command Injection Vulnerability
Cisco

Cisco HyperFlex HX Installer Virtual Machine contains an insufficient input validation vulnerability which could allow an attacker to execute commands on an affected device as the root user.

CWE-78 · OS command injection
Refsnvd.nist.gov
Federal remediation due 2021-11-17
CVE-2020-9859
2021-11-03
Apple Multiple Products Code Execution Vulnerability
Apple

Apple iOS, iPadOS, macOS, watchOS, and tvOS contain an unspecified vulnerability that may allow an application to execute code with kernel privileges.

CWE-415
Refsnvd.nist.gov
Federal remediation due 2022-05-03
CVE-2020-9819
2021-11-03
Apple iOS, iPadOS, and watchOS Memory Corruption Vulnerability
Apple

Apple iOS, iPadOS, and watchOS Mail contains a memory corruption vulnerability that may allow heap corruption when processing a maliciously crafted mail message.

CWE-787 · Out-of-bounds write
Refsnvd.nist.gov
Federal remediation due 2022-05-03
CVE-2020-9818
2021-11-03
Apple iOS, iPadOS, and watchOS Out-of-Bounds Write Vulnerability
Apple

Apple iOS, iPadOS, and watchOS Mail contains an out-of-bounds write vulnerability which may allow memory modification or application termination when processing a maliciously crafted mail message.

CWE-787 · Out-of-bounds write
Refsnvd.nist.gov
Federal remediation due 2022-05-03
CVE-2020-8657
2021-11-03
EyesOfNetwork Use of Hard-Coded Credentials Vulnerability
EyesOfNetwork

EyesOfNetwork contains a use of hard-coded credentials vulnerability, as it uses the same API key by default. Exploitation allows an attacker to calculate or guess the admin access token.

CWE-798 · Hard-coded credentials
Refsnvd.nist.gov
Federal remediation due 2022-05-03
CVE-2020-8655
2021-11-03
EyesOfNetwork Improper Privilege Management Vulnerability
EyesOfNetwork

EyesOfNetwork contains an improper privilege management vulnerability that may allow a user to run commands as root via a crafted Nmap Scripting Engine (NSE) script to nmap7.

CWE-269 · Improper privilege management
Refsnvd.nist.gov
Federal remediation due 2022-05-03
CVE-2020-8644
2021-11-03
PlaySMS Server-Side Template Injection Vulnerability
PlaySMS

PlaySMS contains a server-side template injection vulnerability that allows for remote code execution.

CWE-94 · Code injection
Refsnvd.nist.gov
Federal remediation due 2022-05-03
CVE-2020-8599
2021-11-03
Trend Micro Apex One and OfficeScan Authentication Bypass Vulnerability
Trend Micro

Trend Micro Apex One and OfficeScan server contain a vulnerable EXE file that could allow a remote attacker to write data to a path on affected installations and bypass root login.

Refsnvd.nist.gov
Federal remediation due 2022-05-03
CVE-2020-8515
2021-11-03
Multiple DrayTek Vigor Routers Web Management Page Vulnerability
DrayTek / Multiple Vigor Routers

DrayTek Vigor3900, Vigor2960, and Vigor300B routers contain an unspecified vulnerability that allows for remote code execution.

CWE-78 · OS command injection
Refsnvd.nist.gov
Federal remediation due 2022-05-03
CVE-2020-8468
2021-11-03
Trend Micro Multiple Products Content Validation Escape Vulnerability
Trend Micro / Apex One, OfficeScan and Worry-Free Business Security Agents

Trend Micro Apex One, OfficeScan, and Worry-Free Business Security agents contain a content validation escape vulnerability that could allow an attacker to manipulate certain agent client components.

CWE-74
Refsnvd.nist.gov
Federal remediation due 2022-05-03
CVE-2020-8467
2021-11-03
Trend Micro Apex One and OfficeScan Remote Code Execution Vulnerability
Trend Micro

Trend Micro Apex One and OfficeScan contain an unspecified vulnerability within a migration tool component that allows for remote code execution.

Refsnvd.nist.gov
Federal remediation due 2022-05-03
CVE-2020-8260
2021-11-03
Ivanti Pulse Connect Secure Code Execution Vulnerability
Ivanti

Pulse Connect Secure contains an unspecified vulnerability that allows an authenticated attacker to perform code execution using uncontrolled gzip extraction.

CWE-434 · Unrestricted file upload
RefsReference CISA's ED 21-03 (
Federal remediation due 2022-05-03
CVE-2020-8243
2021-11-03
Ivanti Pulse Connect Secure Code Execution Vulnerability
Ivanti

Ivanti Pulse Connect Secure contains an unspecified vulnerability in the admin web interface that could allow an authenticated attacker to upload a custom template to perform code execution.

CWE-94 · Code injection
RefsReference CISA's ED 21-03 (
Federal remediation due 2022-05-03
CVE-2020-8196
2021-11-03
Citrix ADC, Gateway, and SD-WAN WANOP Appliance Information Disclosure Vulnerability
Citrix / Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance

Citrix ADC, Citrix Gateway, and multiple Citrix SD-WAN WANOP appliance models contain an information disclosure vulnerability.

CWE-284 · Improper access control
Refsnvd.nist.gov
Federal remediation due 2022-05-03
CVE-2020-8195
2021-11-03
Citrix ADC, Gateway, and SD-WAN WANOP Appliance Information Disclosure Vulnerability
Citrix / Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance

Citrix ADC, Citrix Gateway, and multiple Citrix SD-WAN WANOP appliance models contain an information disclosure vulnerability.

CWE-20 · Improper input validation
Refsnvd.nist.gov
Federal remediation due 2022-05-03
CVE-2020-8193
2021-11-03
Citrix ADC, Gateway, and SD-WAN WANOP Appliance Authorization Bypass Vulnerability
Citrix / Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance

Citrix ADC, Citrix Gateway, and multiple Citrix SD-WAN WANOP appliance models contain an authorization bypass vulnerability that may allow unauthenticated access to certain URL endpoints. The attacker must have access to the NetScaler IP (NSIP) in order to perform exploitation.

CWE-284 · Improper access control
Refsnvd.nist.gov
Federal remediation due 2022-05-03
CVE-2020-7961
2021-11-03
Liferay Portal Deserialization of Untrusted Data Vulnerability
Liferay

Liferay Portal contains a deserialization of untrusted data vulnerability that allows remote attackers to execute code via JSON web services.

CWE-502 · Deserialization of untrusted data
Refsnvd.nist.gov
Federal remediation due 2022-05-03
CVE-2020-6820
2021-11-03
Mozilla Firefox And Thunderbird Use-After-Free Vulnerability
Mozilla

Mozilla Firefox and Thunderbird contain a race condition vulnerability when handling a ReadableStream under certain conditions. The race condition creates a use-after-free vulnerability, causing unspecified impacts.

CWE-362
Refsnvd.nist.gov
Federal remediation due 2022-05-03
CVE-2020-6819
2021-11-03
Mozilla Firefox And Thunderbird Use-After-Free Vulnerability
Mozilla

Mozilla Firefox and Thunderbird contain a race condition vulnerability when running the nsDocShell destructor under certain conditions. The race condition creates a use-after-free vulnerability, causing unspecified impacts.

CWE-362CWE-416 · Use after free
Refsnvd.nist.gov
Federal remediation due 2022-05-03
CVE-2020-6418
2021-11-03
Google Chromium V8 Type Confusion Vulnerability
Google

Google Chromium V8 Engine contains a type confusion vulnerability allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

CWE-843 · Type confusion
Refsnvd.nist.gov
Federal remediation due 2022-05-03
CVE-2020-6287
2021-11-03
SAP NetWeaver Missing Authentication for Critical Function Vulnerability
SAP

SAP NetWeaver Application Server Java Platforms contains a missing authentication for critical function vulnerability allowing unauthenticated access to execute configuration tasks and create administrative users.

CWE-306 · Missing authentication
Refsnvd.nist.gov
Federal remediation due 2022-05-03
CVE-2020-6207
2021-11-03
SAP Solution Manager Missing Authentication for Critical Function Vulnerability
SAP

SAP Solution Manager User Experience Monitoring contains a missing authentication for critical function vulnerability which results in complete compromise of all SMDAgents connected to the Solution Manager.

CWE-306 · Missing authentication
Refsnvd.nist.gov
Federal remediation due 2022-05-03
CVE-2020-5902
2021-11-03
F5 BIG-IP Traffic Management User Interface (TMUI) Remote Code Execution VulnerabilityRansomware
F5

F5 BIG-IP Traffic Management User Interface (TMUI) contains a remote code execution vulnerability in undisclosed pages.

CWE-22 · Path traversal
Refsnvd.nist.gov
Federal remediation due 2022-05-03
CVE-2020-5849
2021-11-03
Unraid Authentication Bypass Vulnerability
Unraid

Unraid contains an authentication bypass vulnerability that allows attackers to gain access to the administrative interface. This CVE is chainable with CVE-2020-5847 for remote code execution.

CWE-287 · Improper authenticationCWE-697
Refsnvd.nist.gov
Federal remediation due 2022-05-03
CVE-2020-5847
2021-11-03
Unraid Remote Code Execution Vulnerability
Unraid

Unraid contains a vulnerability due to the insecure use of the extract PHP function that can be abused to execute remote code as root. This CVE is chainable with CVE-2020-5849 for initial access.

Refsnvd.nist.gov
Federal remediation due 2022-05-03
CVE-2020-5735
2021-11-03
Amcrest Cameras and NVR Stack-based Buffer Overflow Vulnerability
Amcrest / Cameras and Network Video Recorder (NVR)

Amcrest cameras and NVR contain a stack-based buffer overflow vulnerability through port 37777 that allows an unauthenticated, remote attacker to crash the device and possibly execute code.

CWE-121 · Stack buffer overflow
Refsnvd.nist.gov
Federal remediation due 2022-05-03
CVE-2020-4430
2021-11-03
IBM Data Risk Manager Directory Traversal Vulnerability
IBM

IBM Data Risk Manager contains a directory traversal vulnerability that could allow a remote authenticated attacker to traverse directories and send a specially crafted URL request to download arbitrary files from the system.

CWE-22 · Path traversal
Refsnvd.nist.gov
Federal remediation due 2022-05-03
CVE-2020-4428
2021-11-03
IBM Data Risk Manager Remote Code Execution Vulnerability
IBM

IBM Data Risk Manager contains an unspecified vulnerability which could allow a remote, authenticated attacker to execute commands on the system.�

CWE-78 · OS command injection
Refsnvd.nist.gov
Federal remediation due 2022-05-03
CVE-2020-4427
2021-11-03
IBM Data Risk Manager Security Bypass Vulnerability
IBM

IBM Data Risk Manager contains a security bypass vulnerability that could allow a remote attacker to bypass security restrictions when configured with SAML authentication. By sending a specially crafted HTTP request, an attacker could exploit this vulnerability to bypass the authentication process and gain full administrative access to the system.

Refsnvd.nist.gov
Federal remediation due 2022-05-03
CVE-2020-4006
2021-11-03
Multiple VMware Products Command Injection Vulnerability
VMware / Multiple Products

VMware Workspace One Access, Access Connector, Identity Manager, and Identity Manager Connector contain a command injection vulnerability. An attacker with network access to the administrative configurator on port 8443 and a valid password for the configurator administrator account can execute commands with unrestricted privileges on the underlying operating system.

CWE-78 · OS command injection
Refsnvd.nist.gov
Federal remediation due 2022-05-03
CVE-2020-3992
2021-11-03
VMware ESXi OpenSLP Use-After-Free VulnerabilityRansomware
VMware

VMware ESXi OpenSLP contains a use-after-free vulnerability that allows an attacker residing in the management network with access to port 427 to perform remote code execution.

CWE-416 · Use after free
Refsnvd.nist.gov
Federal remediation due 2022-05-03
CVE-2020-3952
2021-11-03
VMware vCenter Server Information Disclosure Vulnerability
VMware

VMware vCenter Server contains an information disclosure vulnerability in the VMware Directory Service (vmdir) when the Platform Services Controller (PSC) does not correctly implement access controls. Successful exploitation allows an attacker with network access to port 389 to extract sensitive information.

CWE-306 · Missing authentication
Refsnvd.nist.gov
Federal remediation due 2022-05-03
CVE-2020-3950
2021-11-03
VMware Multiple Products Privilege Escalation Vulnerability
VMware

VMware Fusion, Remote Console (VMRC) for Mac, and Horizon Client for Mac contain a privilege escalation vulnerability due to improper use of setuid binaries that allows attackers to escalate privileges to root.

CWE-269 · Improper privilege management
Refsnvd.nist.gov
Federal remediation due 2022-05-03
CVE-2020-3580
2021-11-03
Cisco ASA and FTD Cross-Site Scripting (XSS) VulnerabilityRansomware
Cisco / Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD)

Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) contain an insufficient input validation vulnerability for user-supplied input by the web services interface. Successful exploitation could allow an attacker to perform cross-site scripting (XSS) in the context of the interface or access sensitive browser-based information.

CWE-79 · Cross-site scripting
Refsnvd.nist.gov
Federal remediation due 2022-05-03
CVE-2020-3569
2021-11-03
Cisco IOS XR Software DVMRP Memory Exhaustion Vulnerability
Cisco

Cisco IOS XR Distance Vector Multicast Routing Protocol (DVMRP) incorrectly handles Internet Group Management Protocol (IGMP) packets. Exploitation could allow an unauthenticated, remote attacker to immediately crash the IGMP process or make it consume available memory and eventually crash.

CWE-400
Refsnvd.nist.gov
Federal remediation due 2022-05-03
CVE-2020-3566
2021-11-03
Cisco IOS XR Software DVMRP Memory Exhaustion Vulnerability
Cisco

Cisco IOS XR Distance Vector Multicast Routing Protocol (DVMRP) incorrectly handles Internet Group Management Protocol (IGMP) packets. Exploitation could allow an unauthenticated, remote attacker to immediately crash the IGMP process or make it consume available memory and eventually crash.

CWE-400
Refsnvd.nist.gov
Federal remediation due 2022-05-03
CVE-2020-3452
2021-11-03
Cisco ASA and FTD Read-Only Path Traversal Vulnerability
Cisco / Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD)

Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) contain an improper input validation vulnerability when HTTP requests process URLs. An attacker could exploit this vulnerability by sending a crafted HTTP request containing directory traversal character sequences to an affected device. A successful exploit could allow the attacker to view arbitrary files within the web services file system on the targeted device.

CWE-20 · Improper input validation
Refsnvd.nist.gov
Federal remediation due 2022-05-03
CVE-2020-3161
2021-11-03
Cisco IP Phones Web Server Remote Code Execution and Denial-of-Service Vulnerability
Cisco

Cisco IP Phones contain an improper input validation vulnerability for HTTP requests. Exploitation could allow an attacker to execute code remotely with root privileges or cause a denial-of-service (DoS) condition.

CWE-20 · Improper input validation
Refsnvd.nist.gov
Federal remediation due 2022-05-03
CVE-2020-3118
2021-11-03
Cisco IOS XR Software Discovery Protocol Format String Vulnerability
Cisco

Cisco IOS XR improperly validates string input from certain fields in Cisco Discovery Protocol messages. Exploitation could allow an unauthenticated, adjacent attacker to execute code with administrative privileges or cause a reload on an affected device.

CWE-134
Refsnvd.nist.gov
Federal remediation due 2022-05-03
CVE-2020-29583
2021-11-03
Zyxel Multiple Products Use of Hard-Coded Credentials Vulnerability
Zyxel

Zyxel firewalls (ATP, USG, VM) and AP Controllers (NXC2500 and NXC5500) contain a use of hard-coded credentials vulnerability in an undocumented account ("zyfwp") with an unchangeable password.

CWE-522
Refsnvd.nist.gov
Federal remediation due 2022-05-03
CVE-2020-29557
2021-11-03
D-Link DIR-825 R1 Devices Buffer Overflow Vulnerability
D-Link

D-Link DIR-825 R1 devices contain a buffer overflow vulnerability in the web interface that may allow for remote code execution.

CWE-119 · Memory buffer bounds
Refsnvd.nist.gov
Federal remediation due 2022-05-03
CVE-2020-27950
2021-11-03
Apple Multiple Products Memory Initialization Vulnerability
Apple

Apple iOS, iPadOS, macOS, and watchOS contain a memory initialization vulnerability that may allow a malicious application to disclose kernel memory.

CWE-665
Refsnvd.nist.gov
Federal remediation due 2022-05-03
CVE-2020-27932
2021-11-03
Apple Multiple Products Type Confusion Vulnerability
Apple

Apple iOS, iPadOS, macOS, and watchOS contain a type confusion vulnerability that may allow a malicious application to execute code with kernel privileges.

CWE-843 · Type confusion
Refsnvd.nist.gov
Federal remediation due 2022-05-03
CVE-2020-27930
2021-11-03
Apple Multiple Products Memory Corruption Vulnerability
Apple

Apple iOS, iPadOS, macOS, and watchOS FontParser contain a memory corruption vulnerability which may allow for code execution when processing maliciously crafted front.

CWE-787 · Out-of-bounds write
Refsnvd.nist.gov
Federal remediation due 2022-05-03
CVE-2020-26919
2021-11-03
Netgear JGS516PE Devices Missing Function Level Access Control Vulnerability
NETGEAR

Netgear JGS516PE devices contain a missing function level access control vulnerability.

Refsnvd.nist.gov
Federal remediation due 2022-05-03
CVE-2020-2555
2021-11-03
Oracle Multiple Products Remote Code Execution Vulnerability
Oracle

Multiple Oracle products contain a remote code execution vulnerability that allows an unauthenticated attacker with network access via T3 or HTTP to takeover the affected system. Impacted Oracle products: Oracle Coherence in Fusion Middleware, Oracle Utilities Framework, Oracle Retail Assortment Planning, Oracle Commerce, Oracle Communications Diameter Signaling Router (DSR).

CWE-502 · Deserialization of untrusted data
Refsnvd.nist.gov
Federal remediation due 2022-05-03
Prev31 / 34Next