Rosetta Intel
Datasets/KEV CatalogThreat ActorsAttack Surface
Rosetta Lab ↗Blur Horizon LLC
Datasets

KEV Catalog

CISA, queryable

Known exploited vulnerabilities as a queryable table — by CVE, vendor or product.

1685 entries·352 Ransomware·Updated 2026-08-27

1685 results·Page 33 / 34

CVE-2019-8394
2021-11-03
Zoho ManageEngine ServiceDesk Plus (SDP) File Upload Vulnerability
Zoho

Zoho ManageEngine ServiceDesk Plus (SDP) contains an unspecified vulnerability that allows remote users to upload files via login page customization.

CWE-434 · Unrestricted file upload
Refsnvd.nist.gov
Federal remediation due 2022-05-03
CVE-2019-7481
2021-11-03
SonicWall SMA100 SQL Injection VulnerabilityRansomware
SonicWall

SonicWall SMA100 contains a SQL injection vulnerability allowing an unauthenticated user to gain read-only access to unauthorized resources.

CWE-89 · SQL injection
Refsnvd.nist.gov
Federal remediation due 2022-05-03
CVE-2019-6223
2021-11-03
Apple iOS and macOS Group Facetime Vulnerability
Apple

Apple iOS and macOS Group FaceTime contains an unspecified vulnerability where the call initiator can cause the recipient's Apple device to answer unknowingly or without user interaction.

Refsnvd.nist.gov
Federal remediation due 2022-05-03
CVE-2019-5591
2021-11-03
Fortinet FortiOS Default Configuration VulnerabilityRansomware
Fortinet

Fortinet FortiOS contains a default configuration vulnerability that may allow an unauthenticated attacker on the same subnet to intercept sensitive information by impersonating the Lightweight Directory Access Protocol (LDAP) server.

CWE-306 · Missing authentication
Refsnvd.nist.gov
Federal remediation due 2022-05-03
CVE-2019-5544
2021-11-03
VMware ESXi and Horizon DaaS OpenSLP Heap-Based Buffer Overflow VulnerabilityRansomware
VMware

VMware ESXi and Horizon Desktop as a Service (DaaS) OpenSLP contains a heap-based buffer overflow vulnerability that allows an attacker with network access to port 427 to overwrite the heap of the OpenSLP service to perform remote code execution.

CWE-787 · Out-of-bounds write
Refsnvd.nist.gov
Federal remediation due 2022-05-03
CVE-2019-4716
2021-11-03
IBM Planning Analytics Remote Code Execution Vulnerability
IBM

IBM Planning Analytics is vulnerable to a configuration overwrite that allows an unauthenticated user to login as "admin", and then execute code as root or SYSTEM via TM1 scripting.

CWE-94 · Code injection
Refsnvd.nist.gov
Federal remediation due 2022-05-03
CVE-2019-3398
2021-11-03
Atlassian Confluence Server and Data Center Path Traversal Vulnerability
Atlassian

Atlassian Confluence Server and Data Center contain a path traversal vulnerability in the downloadallattachments resource that may allow a privileged, remote attacker to write files. Exploitation can lead to remote code execution.

CWE-22 · Path traversal
Refsnvd.nist.gov
Federal remediation due 2022-05-03
CVE-2019-3396
2021-11-03
Atlassian Confluence Server and Data Center Server-Side Template Injection VulnerabilityRansomware
Atlassian / Confluence Server and Data Server

Atlassian Confluence Server and Data Center contain a server-side template injection vulnerability that may allow an attacker to achieve path traversal and remote code execution.

CWE-22 · Path traversal
Refsnvd.nist.gov
Federal remediation due 2022-05-03
CVE-2019-2215
2021-11-03
Android Kernel Use-After-Free Vulnerability
Android

Android Kernel contains a use-after-free vulnerability in binder.c that allows for privilege escalation from an application to the Linux Kernel. This vulnerability was observed chained with CVE-2020-0041 and CVE-2020-0069 under exploit chain "AbstractEmu."

CWE-416 · Use after free
Refsnvd.nist.gov
Federal remediation due 2022-05-03
CVE-2019-20085
2021-11-03
TVT NVMS-1000 Directory Traversal Vulnerability
TVT

TVT devices utilizing NVMS-1000 software contain a directory traversal vulnerability via GET /.. requests.

CWE-22 · Path traversal
Refsnvd.nist.gov
Federal remediation due 2022-05-03
CVE-2019-19781
2021-11-03
Citrix ADC, Gateway, and SD-WAN WANOP Appliance Code Execution VulnerabilityRansomware
Citrix / Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance

Citrix ADC, Citrix Gateway, and multiple Citrix SD-WAN WANOP appliance models contain an unspecified vulnerability that could allow an unauthenticated attacker to perform code execution.

CWE-22 · Path traversal
Refsnvd.nist.gov
Federal remediation due 2022-05-03
CVE-2019-19356
2021-11-03
Netis WF2419 Devices Remote Code Execution Vulnerability
Netis

Netis WF2419 devices contains an unspecified vulnerability that allows an attacker to perform remote code execution as root through the router's web management page.

CWE-78 · OS command injection
Refsnvd.nist.gov
Federal remediation due 2022-05-03
CVE-2019-18988
2021-11-03
TeamViewer Desktop Bypass Remote Login Vulnerability
TeamViewer

TeamViewer Desktop allows for bypass of remote-login access control because the same AES key is used for different customers' installations. If an attacker were to know this key, they could decrypt protected information stored in registry or configuration files or decryption of the Unattended Access password to the system (which allows for remote login to the system).

CWE-521
Refsnvd.nist.gov
Federal remediation due 2022-05-03
CVE-2019-18935
2021-11-03
Progress Telerik UI for ASP.NET AJAX Deserialization of Untrusted Data VulnerabilityRansomware
Progress

Progress Telerik UI for ASP.NET AJAX contains a deserialization of untrusted data vulnerability through RadAsyncUpload which leads to code execution on the server in the context of the w3wp.exe process.

CWE-502 · Deserialization of untrusted data
Refsnvd.nist.gov
Federal remediation due 2022-05-03
CVE-2019-18187
2021-11-03
Trend Micro OfficeScan Directory Traversal Vulnerability
Trend Micro

Trend Micro OfficeScan contains a directory traversal vulnerability by extracting files from a zip file to a specific folder on the OfficeScan server, leading to remote code execution.

CWE-22 · Path traversal
Refsnvd.nist.gov
Federal remediation due 2022-05-03
CVE-2019-17558
2021-11-03
Apache Solr VelocityResponseWriter Plug-In Remote Code Execution Vulnerability
Apache

The Apache Solr VelocityResponseWriter plug-in contains an unspecified vulnerability which can allow for remote code execution.

CWE-74
Refsnvd.nist.gov
Federal remediation due 2022-05-03
CVE-2019-17026
2021-11-03
Mozilla Firefox And Thunderbird Type Confusion Vulnerability
Mozilla

Mozilla Firefox and Thunderbird contain a type confusion vulnerability due to incorrect alias information in the IonMonkey JIT compiler when setting array elements.

CWE-843 · Type confusion
Refsnvd.nist.gov
Federal remediation due 2022-05-03
CVE-2019-16759
2021-11-03
vBulletin PHP Module Remote Code Execution Vulnerability
vBulletin

The PHP module within vBulletin contains an unspecified vulnerability that allows for remote code execution via the widgetConfig[code] parameter in an ajax/render/widget_php routestring request.

CWE-94 · Code injection
Refsnvd.nist.gov
Federal remediation due 2022-05-03
CVE-2019-1653
2021-11-03
Cisco Small Business RV320 and RV325 Routers Information Disclosure Vulnerability
Cisco

Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers contain improper access controls for URLs. Exploitation could allow an attacker to download the router configuration or detailed diagnostic information.

CWE-284 · Improper access control
Refsnvd.nist.gov
Federal remediation due 2022-05-03
CVE-2019-16256
2021-11-03
SIMalliance Toolbox Browser Command Injection Vulnerability
SIMalliance

SIMalliance Toolbox Browser contains an command injection vulnerability that could allow remote attackers to retrieve location and IMEI information or execute a range of other attacks by modifying the attack message.

Refsnvd.nist.gov
Federal remediation due 2022-05-03
CVE-2019-15949
2021-11-03
Nagios XI Remote Code Execution Vulnerability
Nagios

Nagios XI contains a remote code execution vulnerability in which a user can modify the check_plugin executable and insert malicious commands to execute as root.

CWE-78 · OS command injection
Refsnvd.nist.gov
Federal remediation due 2022-05-03
CVE-2019-15752
2021-11-03
Docker Desktop Community Edition Privilege Escalation Vulnerability
Docker

Docker Desktop Community Edition contains a vulnerability that may allow local users to escalate privileges by placing a trojan horse docker-credential-wincred.exe file in %PROGRAMDATA%\DockerDesktop\version-bin\.

CWE-732
Refsnvd.nist.gov
Federal remediation due 2022-05-03
CVE-2019-1429
2021-11-03
Microsoft Internet Explorer Scripting Engine Memory Corruption Vulnerability
Microsoft

Microsoft Internet Explorer contains a memory corruption vulnerability which can allow for remote code execution in the context of the current user.

CWE-416 · Use after freeCWE-787 · Out-of-bounds write
Refsnvd.nist.gov
Federal remediation due 2022-05-03
CVE-2019-1367
2021-11-03
Microsoft Internet Explorer Scripting Engine Memory Corruption VulnerabilityRansomware
Microsoft

Microsoft Internet Explorer contains a memory corruption vulnerability in how the scripting engine handles objects in memory. Successful exploitation allows for remote code execution in the context of the current user.

CWE-787 · Out-of-bounds write
Refsnvd.nist.gov
Federal remediation due 2022-05-03
CVE-2019-13608
2021-11-03
Citrix StoreFront Server XML External Entity (XXE) Processing VulnerabilityRansomware
Citrix

Citrix StoreFront Server contains an XML External Entity (XXE) processing vulnerability that may allow an unauthenticated attacker to retrieve potentially sensitive information.

CWE-611
Refsnvd.nist.gov
Federal remediation due 2022-05-03
CVE-2019-1215
2021-11-03
Microsoft Windows Privilege Escalation VulnerabilityRansomware
Microsoft

Microsoft Windows contains an unspecified vulnerability due to the way ws2ifsl.sys (Winsock) handles objects in memory, allowing for privilege escalation. Successful exploitation allows an attacker to execute code with elevated privileges.

Refsnvd.nist.gov
Federal remediation due 2022-05-03
CVE-2019-1214
2021-11-03
Microsoft Windows Privilege Common Log File System (CLFS) Escalation Vulnerability
Microsoft

Microsoft Windows Common Log File System (CLFS) driver improperly handles objects in memory which can allow for privilege escalation.

Refsnvd.nist.gov
Federal remediation due 2022-05-03
CVE-2019-11634
2021-11-03
Citrix Workspace Application and Receiver for Windows Remote Code Execution VulnerabilityRansomware
Citrix

Citrix Workspace Application and Receiver for Windows contains remote code execution vulnerability resulting from local drive access preferences not being enforced into the clients' local drives.

Refsnvd.nist.gov
Federal remediation due 2022-05-03
CVE-2019-11580
2021-11-03
Atlassian Crowd and Crowd Data Center Remote Code Execution VulnerabilityRansomware
Atlassian

Atlassian Crowd and Crowd Data Center contain a remote code execution vulnerability resulting from a pdkinstall development plugin being incorrectly enabled in release builds.

Refsnvd.nist.gov
Federal remediation due 2022-05-03
CVE-2019-11539
2021-11-03
Ivanti Pulse Connect Secure and Policy Secure Command Injection VulnerabilityRansomware
Ivanti / Pulse Connect Secure and Pulse Policy Secure

Ivanti Pulse Connect Secure and Policy Secure allows an authenticated attacker from the admin web interface to inject and execute commands.

CWE-78 · OS command injection
Refsnvd.nist.gov
Federal remediation due 2022-05-03
CVE-2019-11510
2021-11-03
Ivanti Pulse Connect Secure Arbitrary File Read VulnerabilityRansomware
Ivanti

Ivanti Pulse Connect Secure contains an arbitrary file read vulnerability that allows an unauthenticated remote attacker with network access via HTTPS to send a specially crafted URI.

CWE-22 · Path traversal
RefsReference CISA's ED 21-03 (
Federal remediation due 2022-05-03
CVE-2019-0863
2021-11-03
Microsoft Windows Error Reporting (WER) Privilege Escalation Vulnerability
Microsoft

Microsoft Windows Error Reporting (WER) contains a privilege escalation vulnerability due to the way it handles files, allowing for code execution in kernel mode.

Refsnvd.nist.gov
Federal remediation due 2022-05-03
CVE-2019-0859
2021-11-03
Microsoft Win32k Privilege Escalation Vulnerability
Microsoft

Microsoft Win32k fails to properly handle objects in memory causing privilege escalation. Successful exploitation allows an attacker to run code in kernel mode.

Refsnvd.nist.gov
Federal remediation due 2022-05-03
CVE-2019-0808
2021-11-03
Microsoft Win32k Privilege Escalation Vulnerability
Microsoft

Microsoft Win32k contains a privilege escalation vulnerability due to the component failing to properly handle objects in memory. Successful exploitation allows an attacker to run code in kernel mode.

Refsnvd.nist.gov
Federal remediation due 2022-05-03
CVE-2019-0803
2021-11-03
Microsoft Win32k Privilege Escalation VulnerabilityRansomware
Microsoft

Microsoft Win32k contains an unspecified vulnerability due to it failing to properly handle objects in memory causing privilege escalation. Successful exploitation allows an attacker to run code in kernel mode.

Refsnvd.nist.gov
Federal remediation due 2022-05-03
CVE-2019-0797
2021-11-03
Microsoft Win32k Privilege Escalation Vulnerability
Microsoft

Microsoft Win32k contains a privilege escalation vulnerability when the Win32k component fails to properly handle objects in memory. Successful exploitation allows an attacker to execute code in kernel mode.

Refsnvd.nist.gov
Federal remediation due 2022-05-03
CVE-2019-0708
2021-11-03
Microsoft Remote Desktop Services Remote Code Execution VulnerabilityRansomware
Microsoft

Microsoft Remote Desktop Services, formerly known as Terminal Service, contains an unspecified vulnerability that allows an unauthenticated attacker to connect to the target system using RDP and send specially crafted requests. Successful exploitation allows for remote code execution. The vulnerability is also known under the moniker of BlueKeep.

CWE-416 · Use after free
Refsnvd.nist.gov
Federal remediation due 2022-05-03
CVE-2019-0604
2021-11-03
Microsoft SharePoint Remote Code Execution VulnerabilityRansomware
Microsoft

Microsoft SharePoint fails to check the source markup of an application package. An attacker who successfully exploits the vulnerability could run remote code in the context of the SharePoint application pool and the SharePoint server farm account.

CWE-20 · Improper input validation
Refsnvd.nist.gov
Federal remediation due 2022-05-03
CVE-2019-0541
2021-11-03
Microsoft MSHTML Remote Code Execution Vulnerability
Microsoft

Microsoft MSHTML engine contains an improper input validation vulnerability that allows for remote code execution vulnerability.

CWE-77 · Command injection
Refsnvd.nist.gov
Federal remediation due 2022-05-03
CVE-2019-0211
2021-11-03
Apache HTTP Server Privilege Escalation Vulnerability
Apache

Apache HTTP Server, with MPM event, worker or prefork, code executing in less-privileged child processes or threads (including scripts executed by an in-process scripting interpreter) could execute code with the privileges of the parent process (usually root) by manipulating the scoreboard.

CWE-416 · Use after free
Refsnvd.nist.gov
Federal remediation due 2022-05-03
CVE-2018-8653
2021-11-03
Microsoft Internet Explorer Scripting Engine Memory Corruption Vulnerability
Microsoft

Microsoft Internet Explorer contains a memory corruption vulnerability due to how the Scripting Engine handles objects in memory, leading to remote code execution.

CWE-787 · Out-of-bounds write
Refsnvd.nist.gov
Federal remediation due 2022-05-03
CVE-2018-7600
2021-11-03
Drupal Core Remote Code Execution VulnerabilityRansomware
Drupal

Drupal Core contains a remote code execution vulnerability that could allow an attacker to exploit multiple attack vectors on a Drupal site, resulting in complete site compromise.

CWE-20 · Improper input validation
Refsnvd.nist.gov
Federal remediation due 2022-05-03
CVE-2018-6789
2021-11-03
Exim Buffer Overflow VulnerabilityRansomware
Exim

Exim contains a buffer overflow vulnerability in the base64d function part of the SMTP listener that may allow for remote code execution.

CWE-119 · Memory buffer bounds
Refsnvd.nist.gov
Federal remediation due 2022-05-03
CVE-2018-4939
2021-11-03
Adobe ColdFusion Deserialization of Untrusted Data Vulnerability
Adobe

Adobe ColdFusion contains a deserialization of untrusted data vulnerability that could allow for code execution.

CWE-502 · Deserialization of untrusted data
Refsnvd.nist.gov
Federal remediation due 2022-05-03
CVE-2018-4878
2021-11-03
Adobe Flash Player Use-After-Free VulnerabilityRansomware
Adobe

Adobe Flash Player contains a use-after-free vulnerability that could allow for code execution.

CWE-416 · Use after free
Refsnvd.nist.gov
Federal remediation due 2022-05-03
CVE-2018-2380
2021-11-03
SAP Customer Relationship Management (CRM) Path Traversal VulnerabilityRansomware
SAP

SAP Customer Relationship Management (CRM) contains a path traversal vulnerability that allows an attacker to exploit insufficient validation of path information provided by users.

CWE-22 · Path traversal
Refsnvd.nist.gov
Federal remediation due 2022-05-03
CVE-2018-20062
2021-11-03
ThinkPHP "noneCms" Remote Code Execution Vulnerability
ThinkPHP

ThinkPHP "noneCms" contains an unspecified vulnerability that allows for remote code execution through crafted use of the filter parameter.

CWE-20 · Improper input validation
Refsnvd.nist.gov
Federal remediation due 2022-05-03
CVE-2018-18325
2021-11-03
DotNetNuke (DNN) Inadequate Encryption Strength Vulnerability
DotNetNuke (DNN)

DotNetNuke (DNN) contains an inadequate encryption strength vulnerability resulting from the use of a weak encryption algorithm to protect input parameters. This CVE ID resolves an incomplete patch for CVE-2018-15811.

CWE-326
Refsnvd.nist.gov
Federal remediation due 2022-05-03
CVE-2018-15961
2021-11-03
Adobe ColdFusion Unrestricted File Upload Vulnerability
Adobe

Adobe ColdFusion contains an unrestricted file upload vulnerability that could allow for code execution.

CWE-434 · Unrestricted file upload
Refsnvd.nist.gov
Federal remediation due 2022-05-03
CVE-2018-15811
2021-11-03
DotNetNuke (DNN) Inadequate Encryption Strength Vulnerability
DotNetNuke (DNN)

DotNetNuke (DNN) contains an inadequate encryption strength vulnerability resulting from the use of a weak encryption algorithm to protect input parameters.

CWE-326
Refsnvd.nist.gov
Federal remediation due 2022-05-03
Prev33 / 34Next