Rosetta Intel
Datasets/KEV CatalogThreat ActorsAttack Surface
Rosetta Lab ↗Blur Horizon LLC
Datasets

KEV Catalog

CISA, queryable

Known exploited vulnerabilities as a queryable table — by CVE, vendor or product.

1685 entries·352 Ransomware·Updated 2026-08-27

1685 results·Page 32 / 34

CVE-2020-25506
2021-11-03
D-Link DNS-320 Device Command Injection Vulnerability
D-Link

D-Link DNS-320 device contains a command injection vulnerability in the sytem_mgr.cgi component that may allow for remote code execution.

CWE-78 · OS command injection
Refsnvd.nist.gov
Federal remediation due 2022-05-03
CVE-2020-25213
2021-11-03
WordPress File Manager Plugin Remote Code Execution Vulnerability
WordPress

WordPress File Manager plugin contains a remote code execution vulnerability that allows unauthenticated users to execute PHP code and upload malicious files on a target site.

CWE-434 · Unrestricted file upload
Refsnvd.nist.gov
Federal remediation due 2022-05-03
CVE-2020-24557
2021-11-03
Trend Micro Multiple Products Improper Access Control Vulnerability
Trend Micro / Apex One, OfficeScan, and Worry-Free Business Security

Trend Micro Apex One, OfficeScan, and Worry-Free Business Security on Microsoft Windows contain an improper access control vulnerability that may allow an attacker to manipulate a particular product folder to disable the security temporarily, abuse a specific Windows function, and attain privilege escalation.

Refsnvd.nist.gov
Federal remediation due 2022-05-03
CVE-2020-17530
2021-11-03
Apache Struts Remote Code Execution Vulnerability
Apache

Forced Object-Graph Navigation Language (OGNL) evaluation in Apache Struts, when evaluated on raw user input in tag attributes, can lead to remote code execution.

CWE-917
Refsnvd.nist.gov
Federal remediation due 2022-05-03
CVE-2020-17496
2021-11-03
vBulletin PHP Module Remote Code Execution Vulnerability
vBulletin

The PHP module within vBulletin contains an unspecified vulnerability that allows for remote code execution via crafted subWidgets data in an ajax/render/widget_tabbedcontainer_tab_panel request. This CVE ID resolves an incomplete patch for CVE-2019-16759.

CWE-74
Refsnvd.nist.gov
Federal remediation due 2022-05-03
CVE-2020-17144
2021-11-03
Microsoft Exchange Server Remote Code Execution Vulnerability
Microsoft

Microsoft Exchange Server improperly validates cmdlet arguments which allow an attacker to perform remote code execution.

CWE-502 · Deserialization of untrusted data
Refsnvd.nist.gov
Federal remediation due 2022-05-03
CVE-2020-17087
2021-11-03
Microsoft Windows Kernel Privilege Escalation Vulnerability
Microsoft

Microsoft Windows kernel contains an unspecified vulnerability that allows for privilege escalation.

CWE-131
Refsnvd.nist.gov
Federal remediation due 2022-05-03
CVE-2020-16846
2021-11-03
SaltStack Salt Shell Injection Vulnerability
SaltStack

SaltStack Salt allows an unauthenticated user with network access to the Salt API to use shell injections to run code on the Salt API using the SSH client. This vulnerability affects any users running the Salt API.

CWE-78 · OS command injection
Refsnvd.nist.gov
Federal remediation due 2022-05-03
CVE-2020-16017
2021-11-03
Google Chrome Use-After-Free Vulnerability
Google

Google Chrome contains a use-after-free vulnerability that allows a remote attacker, who has compromised the renderer process, to potentially perform a sandbox escape via a crafted HTML page.

CWE-416 · Use after free
Refsnvd.nist.gov
Federal remediation due 2022-05-03
CVE-2020-16013
2021-11-03
Google Chromium V8 Incorrect Implementation Vulnerabililty
Google

Google Chromium V8 Engine contains an inappropriate implementation vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

CWE-787 · Out-of-bounds write
Refsnvd.nist.gov
Federal remediation due 2022-05-03
CVE-2020-16010
2021-11-03
Google Chrome for Android UI Heap Buffer Overflow Vulnerability
Google

Google Chrome for Android UI contains a heap buffer overflow vulnerability that allows a remote attacker, who has compromised the renderer process, to potentially perform a sandbox escape via a crafted HTML page.

CWE-787 · Out-of-bounds write
Refsnvd.nist.gov
Federal remediation due 2022-05-03
CVE-2020-16009
2021-11-03
Google Chromium V8 Type Confusion Vulnerability
Google

Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

CWE-787 · Out-of-bounds writeCWE-843 · Type confusion
Refsnvd.nist.gov
Federal remediation due 2022-05-03
CVE-2020-15999
2021-11-03
Google Chrome FreeType Heap Buffer Overflow Vulnerability
Google

Google Chrome uses FreeType, an open-source software library to render fonts, which contains a heap buffer overflow vulnerability in the function Load_SBit_Png when processing PNG images embedded into fonts. This vulnerability is part of an exploit chain with CVE-2020-17087 on Windows and CVE-2020-16010 on Android.

CWE-787 · Out-of-bounds write
Refsnvd.nist.gov
Federal remediation due 2021-11-17
CVE-2020-15505
2021-11-03
Ivanti MobileIron Multiple Products Remote Code Execution Vulnerability
Ivanti

Ivanti MobileIron's Core & Connector, Sentry, and Monitor and Reporting Database (RDB) products contain an unspecified vulnerability that allows for remote code execution.

CWE-706
Refsnvd.nist.gov
Federal remediation due 2022-05-03
CVE-2020-14883
2021-11-03
Oracle WebLogic Server Unspecified Vulnerability
Oracle

Oracle WebLogic Server contains an unspecified vulnerability in the Console component with high impacts to confidentilaity, integrity, and availability.

Refsnvd.nist.gov
Federal remediation due 2022-05-03
CVE-2020-14882
2021-11-03
Oracle WebLogic Server Remote Code Execution Vulnerability
Oracle

Oracle WebLogic Server contains an unspecified vulnerability, which is assessed to allow for remote code execution, based on this vulnerability being related to CVE-2020-14750.

Refsnvd.nist.gov
Federal remediation due 2022-05-03
CVE-2020-14871
2021-11-03
Oracle Solaris and Zettabyte File System (ZFS) Unspecified Vulnerability
Oracle

Oracle Solaris and Oracle ZFS Storage Appliance Kit contain an unspecified vulnerability causing high impacts to confidentiality, integrity, and availability of affected systems.

CWE-787 · Out-of-bounds write
Refsnvd.nist.gov
Federal remediation due 2022-05-03
CVE-2020-14750
2021-11-03
Oracle WebLogic Server Remote Code Execution Vulnerability
Oracle

Oracle WebLogic Server contains an unspecified vulnerability allowing an unauthenticated attacker to perform remote code execution. This vulnerability is related to CVE-2020-14882.

Refsnvd.nist.gov
Federal remediation due 2022-05-03
CVE-2020-1472
2021-11-03
Microsoft Netlogon Privilege Escalation VulnerabilityRansomware
Microsoft

Microsoft's Netlogon Remote Protocol (MS-NRPC) contains a privilege escalation vulnerability when an attacker establishes a vulnerable Netlogon secure channel connection to a domain controller. An attacker who successfully exploits the vulnerability could run a specially crafted application on a device on the network. The vulnerability is also known under the moniker of Zerologon.

CWE-330
RefsReference CISA's ED 20-04 (
Federal remediation due 2022-05-03
CVE-2020-1464
2021-11-03
Microsoft Windows Spoofing Vulnerability
Microsoft

Microsoft Windows contains a spoofing vulnerability when Windows incorrectly validates file signatures, allowing an attacker to bypass security features and load improperly signed files.

CWE-347
Refsnvd.nist.gov
Federal remediation due 2022-05-03
CVE-2020-1380
2021-11-03
Microsoft Internet Explorer Scripting Engine Memory Corruption Vulnerability
Microsoft

Microsoft Internet Explorer contains a memory corruption vulnerability which can allow for remote code execution in the context of the current user.

CWE-787 · Out-of-bounds write
Refsnvd.nist.gov
Federal remediation due 2022-05-03
CVE-2020-1350
2021-11-03
Microsoft Windows DNS Server Remote Code Execution Vulnerability
Microsoft

Microsoft Windows DNS Servers fail to properly handle requests, allowing an attacker to perform remote code execution in the context of the Local System Account. The vulnerability is also known under the moniker of SIGRed.

RefsReference CISA's ED 20-03 (
Federal remediation due 2022-05-03
CVE-2020-12812
2021-11-03
Fortinet FortiOS SSL VPN Improper Authentication VulnerabilityRansomware
Fortinet

Fortinet FortiOS SSL VPN contains an improper authentication vulnerability that may allow a user to login successfully without being prompted for the second factor of authentication (FortiToken) if they change the case in their username.

CWE-178CWE-287 · Improper authentication
Refsnvd.nist.gov
Federal remediation due 2022-05-03
CVE-2020-12271
2021-11-03
Sophos SFOS SQL Injection VulnerabilityRansomware
Sophos

Sophos Firewall operating system (SFOS) firmware contains a SQL injection vulnerability when configured with either the administration (HTTPS) service or the User Portal is exposed on the WAN zone. Successful exploitation may cause remote code execution to exfiltrate usernames and hashed passwords for the local device admin(s), portal admins, and user accounts used for remote access (but not external Active Directory or LDAP passwords).

CWE-89 · SQL injection
Refsnvd.nist.gov
Federal remediation due 2022-05-03
CVE-2020-11738
2021-11-03
WordPress Snap Creek Duplicator Plugin File Download Vulnerability
WordPress

WordPress Snap Creek Duplicator plugin contains a file download vulnerability when an administrator creates a new copy of their site that allows an attacker to download the generated files from their Wordpress dashboard. This vulnerability affects Duplicator and Dulplicator Pro.

CWE-22 · Path traversal
Refsnvd.nist.gov
Federal remediation due 2022-05-03
CVE-2020-11652
2021-11-03
SaltStack Salt Path Traversal Vulnerability
SaltStack

SaltStack Salt contains a path traversal vulnerability in the salt-master process ClearFuncs which allows directory access to authenticated users. Salt users who follow fundamental internet security guidelines and best practices are not affected by this vulnerability.

CWE-22 · Path traversal
Refsnvd.nist.gov
Federal remediation due 2022-05-03
CVE-2020-11651
2021-11-03
SaltStack Salt Authentication Bypass Vulnerability
SaltStack

SaltStack Salt contains an authentication bypass vulnerability in the salt-master process ClearFuncs due to improperly validating method calls. The vulnerability allows a remote user to access some methods without authentication, which can be used to retrieve user tokens from the salt master and/or run commands on salt minions. Salt users who follow fundamental internet security guidelines and best practices are not affected by this vulnerability.

Refsnvd.nist.gov
Federal remediation due 2022-05-03
CVE-2020-1147
2021-11-03
Microsoft .NET Framework, SharePoint, and Visual Studio Remote Code Execution Vulnerability
Microsoft / .NET Framework, SharePoint, Visual Studio

Microsoft .NET Framework, Microsoft SharePoint, and Visual Studio contain a remote code execution vulnerability when the software fails to check the source markup of XML file input. Successful exploitation allows an attacker to execute code in the context of the process responsible for deserialization of the XML content.

Refsnvd.nist.gov
Federal remediation due 2022-05-03
CVE-2020-10987
2021-11-03
Tenda AC1900 Router AC15 Model Remote Code Execution Vulnerability
Tenda

Tenda AC1900 Router AC15 Model contains an unspecified vulnerability that allows remote attackers to execute system commands via the deviceName POST parameter.

CWE-78 · OS command injection
Refsnvd.nist.gov
Federal remediation due 2022-05-03
CVE-2020-1054
2021-11-03
Microsoft Win32k Privilege Escalation Vulnerability
Microsoft

Microsoft Win32k contains a privilege escalation vulnerability when the Windows kernel-mode driver fails to properly handle objects in memory. Successful exploitation allows an attacker to execute code in kernel mode.

CWE-787 · Out-of-bounds write
Refsnvd.nist.gov
Federal remediation due 2022-05-03
CVE-2020-1040
2021-11-03
Microsoft Hyper-V RemoteFX vGPU Remote Code Execution Vulnerability
Microsoft

Microsoft Hyper-V RemoteFX vGPU contains an improper input validation vulnerability due to the host server failing to properly validate input from an authenticated user on a guest operating system. Successful exploitation allows for remote code execution on the host operating system.

CWE-20 · Improper input validation
Refsnvd.nist.gov
Federal remediation due 2022-05-03
CVE-2020-10221
2021-11-03
rConfig OS Command Injection Vulnerability
rConfig

rConfig lib/ajaxHandlers/ajaxAddTemplate.php contains an OS command injection vulnerability that allows remote attackers to execute OS commands via shell metacharacters in the fileName POST parameter.

CWE-78 · OS command injection
Refsnvd.nist.gov
Federal remediation due 2022-05-03
CVE-2020-1020
2021-11-03
Microsoft Windows Adobe Font Manager Library Remote Code Execution Vulnerability
Microsoft

Microsoft Windows Adobe Font Manager Library contains an unspecified vulnerability when handling specially crafted multi-master fonts (Adobe Type 1 PostScript format) that allows for remote code execution for all systems except Windows 10. For systems running Windows 10, an attacker who successfully exploited the vulnerability could execute code in an AppContainer sandbox context with limited privileges and capabilities.

CWE-787 · Out-of-bounds write
Refsnvd.nist.gov
Federal remediation due 2022-05-03
CVE-2020-10199
2021-11-03
Sonatype Nexus Repository Remote Code Execution Vulnerability
Sonatype

Sonatype Nexus Repository contains an unspecified vulnerability that allows for remote code execution.

CWE-917
Refsnvd.nist.gov
Federal remediation due 2022-05-03
CVE-2020-10189
2021-11-03
Zoho ManageEngine Desktop Central File Upload Vulnerability
Zoho

Zoho ManageEngine Desktop Central contains a file upload vulnerability that allows for unauthenticated remote code execution.

CWE-502 · Deserialization of untrusted data
Refsnvd.nist.gov
Federal remediation due 2022-05-03
CVE-2020-10181
2021-11-03
Sumavision EMR Cross-Site Request Forgery (CSRF) Vulnerability
Sumavision / Enhanced Multimedia Router (EMR)

Sumavision Enhanced Multimedia Router (EMR) contains a cross-site request forgery (CSRF) vulnerability allowing the creation of users with elevated privileges as administrator on a device.

CWE-352 · Cross-site request forgery
Refsnvd.nist.gov
Federal remediation due 2022-05-03
CVE-2020-10148
2021-11-03
SolarWinds Orion Authentication Bypass Vulnerability
SolarWinds

SolarWinds Orion API contains an authentication bypass vulnerability that could allow a remote attacker to execute API commands.

CWE-288 · Authentication bypass
Refsnvd.nist.gov
Federal remediation due 2022-05-03
CVE-2020-0986
2021-11-03
Microsoft Windows Kernel Privilege Escalation Vulnerability
Microsoft

Microsoft Windows kernel contains an unspecified vulnerability when handling objects in memory that allows attackers to escalate privileges and execute code in kernel mode.

CWE-787 · Out-of-bounds write
Refsnvd.nist.gov
Federal remediation due 2022-05-03
CVE-2020-0968
2021-11-03
Microsoft Internet Explorer Scripting Engine Memory Corruption VulnerabilityRansomware
Microsoft

Microsoft Internet Explorer contains a memory corruption vulnerability due to how the Scripting Engine handles objects in memory, leading to remote code execution.

CWE-787 · Out-of-bounds write
Refsnvd.nist.gov
Federal remediation due 2022-05-03
CVE-2020-0938
2021-11-03
Microsoft Windows Adobe Font Manager Library Remote Code Execution Vulnerability
Microsoft

Microsoft Windows Adobe Font Manager Library contains an unspecified vulnerability when handling specially crafted multi-master fonts (Adobe Type 1 PostScript format) that allows for remote code execution for all systems except Windows 10. For systems running Windows 10, an attacker who successfully exploited the vulnerability could execute code in an AppContainer sandbox context with limited privileges and capabilities.

CWE-787 · Out-of-bounds write
Refsnvd.nist.gov
Federal remediation due 2022-05-03
CVE-2020-0878
2021-11-03
Microsoft Edge and Internet Explorer Memory Corruption VulnerabilityRansomware
Microsoft

Microsoft Edge and Internet Explorer contain a memory corruption vulnerability that allows attackers to execute code in the context of the current user.

CWE-787 · Out-of-bounds write
Refsnvd.nist.gov
Federal remediation due 2022-05-03
CVE-2020-0688
2021-11-03
Microsoft Exchange Server Validation Key Remote Code Execution VulnerabilityRansomware
Microsoft

Microsoft Exchange Server Validation Key fails to properly create unique keys at install time, allowing for remote code execution.

CWE-287 · Improper authentication
Refsnvd.nist.gov
Federal remediation due 2022-05-03
CVE-2020-0683
2021-11-03
Microsoft Windows Installer Privilege Escalation Vulnerability
Microsoft

Microsoft Windows Installer contains a privilege escalation vulnerability when MSI packages process symbolic links, which allows attackers to bypass access restrictions to add or remove files.

Refsnvd.nist.gov
Federal remediation due 2022-05-03
CVE-2020-0674
2021-11-03
Microsoft Internet Explorer Scripting Engine Memory Corruption Vulnerability
Microsoft

Microsoft Internet Explorer contains a memory corruption vulnerability due to the way the Scripting Engine handles objects in memory. Successful exploitation could allow remote code execution in the context of the current user.

CWE-416 · Use after free
Refsnvd.nist.gov
Federal remediation due 2022-05-03
CVE-2020-0646
2021-11-03
Microsoft .NET Framework Remote Code Execution Vulnerability
Microsoft

Microsoft .NET Framework contains an improper input validation vulnerability that allows for remote code execution.

CWE-91
Refsnvd.nist.gov
Federal remediation due 2022-05-03
CVE-2020-0601
2021-11-03
Microsoft Windows CryptoAPI Spoofing Vulnerability
Microsoft

Microsoft Windows CryptoAPI (Crypt32.dll) contains a spoofing vulnerability in the way it validates Elliptic Curve Cryptography (ECC) certificates. An attacker could exploit the vulnerability by using a spoofed code-signing certificate to sign a malicious executable, making it appear the file was from a trusted, legitimate source. A successful exploit could also allow the attacker to conduct man-in-the-middle attacks and decrypt confidential information on user connections to the affected software. The vulnerability is also known under the moniker of CurveBall.

CWE-295
RefsReference CISA's ED 20-02 (
Federal remediation due 2022-05-03
CVE-2020-0069
2021-11-03
Mediatek Multiple Chipsets Insufficient Input Validation Vulnerability
MediaTek

Multiple MediaTek chipsets contain an insufficient input validation vulnerability and have missing SELinux restrictions in the Command Queue drivers ioctl handlers. This causes an out-of-bounds write leading to privilege escalation. This vulnerability was observed chained with CVE-2019-2215 and CVE-2020-0041 under exploit chain "AbstractEmu."

CWE-787 · Out-of-bounds write
Refsnvd.nist.gov
Federal remediation due 2022-05-03
CVE-2020-0041
2021-11-03
Android Kernel Out-of-Bounds Write Vulnerability
Android

Android Kernel binder_transaction of binder.c contains an out-of-bounds write vulnerability due to an incorrect bounds check that could allow for local privilege escalation. This vulnerability was observed chained with CVE-2019-2215 and CVE-2020-0069 under exploit chain "AbstractEmu."

CWE-20 · Improper input validation
Refsnvd.nist.gov
Federal remediation due 2022-05-03
CVE-2019-9978
2021-11-03
WordPress Social Warfare Plugin Cross-Site Scripting (XSS) Vulnerability
WordPress

WordPress Social Warfare plugin contains a cross-site scripting (XSS) vulnerability that allows for remote code execution. This vulnerability affects Social Warfare and Social Warfare Pro.

CWE-79 · Cross-site scripting
Refsnvd.nist.gov
Federal remediation due 2022-05-03
CVE-2019-9082
2021-11-03
ThinkPHP Remote Code Execution Vulnerability
ThinkPHP

ThinkPHP contains an unspecified vulnerability that allows for remote code execution via public//?s=index/\think\app/invokefunction&function=call_user_func_array&vars[0]=system&vars[1][]= followed by the command.

CWE-306 · Missing authenticationCWE-94 · Code injection
Refsnvd.nist.gov
Federal remediation due 2022-05-03
Prev32 / 34Next