Rosetta Intel
Datasets/KEV CatalogThreat ActorsAttack Surface
Rosetta Lab ↗Blur Horizon LLC
Datasets

KEV Catalog

CISA, queryable

Known exploited vulnerabilities as a queryable table — by CVE, vendor or product.

1685 entries·352 Ransomware·Updated 2026-08-27

1685 results·Page 34 / 34

CVE-2018-14558
2021-11-03
Tenda AC7, AC9, and AC10 Routers Command Injection Vulnerability
Tenda

Tenda AC7, AC9, and AC10 devices contain a command injection vulnerability due to the "formsetUsbUnload" function executes a dosystemCmd function with untrusted input. Successful exploitation allows an attacker to execute OS commands via a crafted goform/setUsbUnload request.

CWE-78 · OS command injection
Refsnvd.nist.gov
Federal remediation due 2022-05-03
CVE-2018-13379
2021-11-03
Fortinet FortiOS SSL VPN Path Traversal VulnerabilityRansomware
Fortinet

Fortinet FortiOS SSL VPN web portal contains a path traversal vulnerability that may allow an unauthenticated attacker to download FortiOS system files through specially crafted HTTP resource requests.

CWE-22 · Path traversal
Refsnvd.nist.gov
Federal remediation due 2022-05-03
CVE-2018-11776
2021-11-03
Apache Struts Remote Code Execution Vulnerability
Apache

Apache Struts contains a vulnerability that allows for remote code execution under two circumstances. One, where the alwaysSelectFullNamespace option is true and the value isn't set for a result defined in underlying configurations and in same time, its upper package configuration have no or wildcard namespace. Or, using URL tag which doesn't have value and action set and in same time, its upper package configuration have no or wildcard namespace.

CWE-20 · Improper input validation
Refsnvd.nist.gov
Federal remediation due 2022-05-03
CVE-2018-0802
2021-11-03
Microsoft Office Memory Corruption VulnerabilityRansomware
Microsoft

Microsoft Office contains a memory corruption vulnerability due to the way objects are handled in memory. Successful exploitation allows for remote code execution in the context of the current user. This vulnerability is known to be chained with CVE-2018-0798.

CWE-787 · Out-of-bounds write
Refsnvd.nist.gov
Federal remediation due 2022-05-03
CVE-2018-0798
2021-11-03
Microsoft Office Memory Corruption Vulnerability
Microsoft

Microsoft Office contains a memory corruption vulnerability due to the way objects are handled in memory. Successful exploitation allows for remote code execution in the context of the current user. This vulnerability is known to be chained with CVE-2018-0802.

CWE-787 · Out-of-bounds write
Refsnvd.nist.gov
Federal remediation due 2022-05-03
CVE-2018-0296
2021-11-03
Cisco Adaptive Security Appliance (ASA) Denial-of-Service Vulnerability
Cisco

Cisco Adaptive Security Appliance (ASA) contains an improper input validation vulnerability with HTTP URLs. Exploitation could allow an attacker to cause a denial-of-service (DoS) condition or information disclosure.

CWE-20 · Improper input validation
Refsnvd.nist.gov
Federal remediation due 2022-05-03
CVE-2018-0171
2021-11-03
Cisco IOS and IOS XE Software Smart Install Remote Code Execution Vulnerability
Cisco

Cisco IOS and IOS XE Software improperly validates packet data, allowing an unauthenticated, remote attacker to trigger a reload of an affected device, cause a denial-of-service (DoS) condition, or perform code execution on the affected device.

CWE-20 · Improper input validation
Refsnvd.nist.gov
Federal remediation due 2022-05-03
CVE-2017-9822
2021-11-03
DotNetNuke (DNN) Remote Code Execution VulnerabilityRansomware
DotNetNuke (DNN)

DotNetNuke (DNN) contains a vulnerability that may allow for remote code execution via cookie deserialization.

CWE-20 · Improper input validation
Refsnvd.nist.gov
Federal remediation due 2022-05-03
CVE-2017-9805
2021-11-03
Apache Struts Deserialization of Untrusted Data Vulnerability
Apache

Apache Struts REST Plugin uses an XStreamHandler with an instance of XStream for deserialization without any type filtering, which can lead to remote code execution when deserializing XML payloads.

CWE-502 · Deserialization of untrusted data
Refsnvd.nist.gov
Federal remediation due 2022-05-03
CVE-2017-9248
2021-11-03
Progress Telerik UI for ASP.NET AJAX and Sitefinity Cryptographic Weakness Vulnerability
Progress

Progress Telerik UI for ASP.NET AJAX and Sitefinity have a cryptographic weakness in Telerik.Web.UI.dll that can be exploited to disclose encryption keys (Telerik.Web.UI.DialogParametersEncryptionKey and/or the MachineKey), perform cross-site-scripting (XSS) attacks, compromise the ASP.NET ViewState, and/or upload and download files.

CWE-522
Refsnvd.nist.gov
Federal remediation due 2022-05-03
CVE-2017-8759
2021-11-03
Microsoft .NET Framework Remote Code Execution Vulnerability
Microsoft

Microsoft .NET Framework contains a remote code execution vulnerability when processing untrusted input that could allow an attacker to take control of an affected system.

CWE-20 · Improper input validation
Refsnvd.nist.gov
Federal remediation due 2022-05-03
CVE-2017-7269
2021-11-03
Microsoft Windows Server Buffer Overflow Vulnerability
Microsoft / Internet Information Services (IIS)

Microsoft Windows Server 2003 R2 contains a buffer overflow vulnerability in Internet Information Services (IIS) 6.0 which allows remote attackers to execute code via a long header beginning with "If: <http://" in a PROPFIND request.

CWE-119 · Memory buffer bounds
Refsnvd.nist.gov
Federal remediation due 2022-05-03
CVE-2017-6327
2021-11-03
Symantec Messaging Gateway Remote Code Execution Vulnerability
Symantec

Symantec Messaging Gateway contains an unspecified vulnerability which can allow for remote code execution. With the ability to perform remote code execution, an attacker may also desire to perform privilege escalating actions.

CWE-20 · Improper input validation
Refsnvd.nist.gov
Federal remediation due 2022-05-03
CVE-2017-5638
2021-11-03
Apache Struts Remote Code Execution VulnerabilityRansomware
Apache

Apache Struts Jakarta Multipart parser allows for malicious file upload using the Content-Type value, leading to remote code execution.

CWE-20 · Improper input validation
Refsnvd.nist.gov
Federal remediation due 2022-05-03
CVE-2017-16651
2021-11-03
Roundcube Webmail File Disclosure Vulnerability
Roundcube

Roundcube Webmail contains a file disclosure vulnerability caused by insufficient input validation in conjunction with file-based attachment plugins, which are used by default.

CWE-552
Refsnvd.nist.gov
Federal remediation due 2022-05-03
CVE-2017-11882
2021-11-03
Microsoft Office Memory Corruption VulnerabilityRansomware
Microsoft

Microsoft Office contains a memory corruption vulnerability that allows remote code execution in the context of the current user.

CWE-119 · Memory buffer bounds
Refsnvd.nist.gov
Federal remediation due 2022-05-03
CVE-2017-11774
2021-11-03
Microsoft Office Outlook Security Feature Bypass Vulnerability
Microsoft

Microsoft Office Outlook contains a security feature bypass vulnerability due to improperly handling objects in memory. Successful exploitation allows an attacker to execute commands.

CWE-119 · Memory buffer bounds
Refsnvd.nist.gov
Federal remediation due 2022-05-03
CVE-2017-0199
2021-11-03
Microsoft Office and WordPad Remote Code Execution VulnerabilityRansomware
Microsoft

Microsoft Office and WordPad contain an unspecified vulnerability due to the way the applications parse specially crafted files. Successful exploitation allows for remote code execution.

Refsnvd.nist.gov
Federal remediation due 2022-05-03
CVE-2017-0143
2021-11-03
Microsoft Windows Server Message Block (SMBv1) Remote Code Execution VulnerabilityRansomware
Microsoft

Microsoft Windows Server Message Block 1.0 (SMBv1) contains an unspecified vulnerability that allows for remote code execution.

CWE-20 · Improper input validation
Refsnvd.nist.gov
Federal remediation due 2022-05-03
CVE-2016-9563
2021-11-03
SAP NetWeaver XML External Entity (XXE) Vulnerability
SAP

SAP NetWeaver Application Server Java Platforms contains an unspecified vulnerability in BC-BMT-BPM-DSK which allows remote, authenticated users to conduct XML External Entity (XXE) attacks.

CWE-611
Refsnvd.nist.gov
Federal remediation due 2022-05-03
CVE-2016-7255
2021-11-03
Microsoft Win32k Privilege Escalation Vulnerability
Microsoft

Microsoft Win32k kernel-mode driver fails to properly handle objects in memory which allows for privilege escalation. Successful exploitation allows an attacker to run code in kernel mode.

CWE-264 · Permissions and access control
Refsnvd.nist.gov
Federal remediation due 2022-05-03
CVE-2016-4437
2021-11-03
Apache Shiro Code Execution Vulnerability
Apache

Apache Shiro contains a vulnerability which may allow remote attackers to execute code or bypass intended access restrictions via an unspecified request parameter when a cipher key has not been configured for the "remember me" feature.

CWE-284 · Improper access control
Refsnvd.nist.gov
Federal remediation due 2022-05-03
CVE-2016-3976
2021-11-03
SAP NetWeaver Directory Traversal Vulnerability
SAP

SAP NetWeaver Application Server Java Platforms contains a directory traversal vulnerability via a ..\ (dot dot backslash) in the fileName parameter to CrashFileDownloadServlet. This allows remote attackers to read files.

CWE-22 · Path traversal
Refsnvd.nist.gov
Federal remediation due 2022-05-03
CVE-2016-3718
2021-11-03
ImageMagick Server-Side Request Forgery (SSRF) Vulnerability
ImageMagick

ImageMagick contains an unspecified vulnerability that allows attackers to perform server-side request forgery (SSRF) via a crafted image.

CWE-20 · Improper input validation
Refsnvd.nist.gov
Federal remediation due 2022-05-03
CVE-2016-3715
2021-11-03
ImageMagick Arbitrary File Deletion Vulnerability
ImageMagick

ImageMagick contains an unspecified vulnerability that could allow users to delete files by using ImageMagick's 'ephemeral' pseudo protocol, which deletes files after reading.

CWE-284 · Improper access control
Refsnvd.nist.gov
Federal remediation due 2022-05-03
CVE-2016-3643
2021-11-03
SolarWinds Virtualization Manager Privilege Escalation Vulnerability
SolarWinds

SolarWinds Virtualization Manager allows for privilege escalation through leveraging a misconfiguration of sudo.

CWE-264 · Permissions and access control
Refsnvd.nist.gov
Federal remediation due 2022-05-03
CVE-2016-3235
2021-11-03
Microsoft Office OLE DLL Side Loading Vulnerability
Microsoft

Microsoft Office Object Linking & Embedding (OLE) dynamic link library (DLL) contains a side loading vulnerability due to it improperly validating input before loading libraries. Successful exploitation allows for remote code execution.

CWE-264 · Permissions and access control
Refsnvd.nist.gov
Federal remediation due 2022-05-03
CVE-2016-0185
2021-11-03
Microsoft Windows Media Center Remote Code Execution Vulnerability
Microsoft

Microsoft Windows Media Center contains a remote code execution vulnerability when Windows Media Center opens a specially crafted Media Center link (.mcl) file that references malicious code.

CWE-20 · Improper input validation
Refsnvd.nist.gov
Federal remediation due 2022-05-03
CVE-2016-0167
2021-11-03
Microsoft Win32k Privilege Escalation VulnerabilityRansomware
Microsoft

Microsoft Win32k contains an unspecified vulnerability that allows for privilege escalation via a crafted application

CWE-264 · Permissions and access control
Refsnvd.nist.gov
Federal remediation due 2022-05-03
CVE-2015-4852
2021-11-03
Oracle WebLogic Server Deserialization of Untrusted Data Vulnerability
Oracle

Oracle WebLogic Server contains a deserialization of untrusted data vulnerability within Apache Commons, which can allow for for remote code execution.

CWE-502 · Deserialization of untrusted data
Refsnvd.nist.gov
Federal remediation due 2022-05-03
CVE-2015-1641
2021-11-03
Microsoft Office Memory Corruption Vulnerability
Microsoft

Microsoft Office contains a memory corruption vulnerability due to failure to properly handle rich text format files in memory. Successful exploitation allows for remote code execution in the context of the current user.

CWE-399 · Resource management
Refsnvd.nist.gov
Federal remediation due 2022-05-03
CVE-2014-1812
2021-11-03
Microsoft Windows Group Policy Preferences Password Privilege Escalation VulnerabilityRansomware
Microsoft

Microsoft Windows Active Directory contains a privilege escalation vulnerability due to the way it distributes passwords that are configured using Group Policy preferences. An authenticated attacker who successfully exploits the vulnerability could decrypt the passwords and use them to elevate privileges on the domain.

CWE-255
Refsnvd.nist.gov
Federal remediation due 2022-05-03
CVE-2012-3152
2021-11-03
Oracle Fusion Middleware Unspecified Vulnerability
Oracle

Oracle Fusion Middleware Reports Developer contains an unspecified vulnerability that allows remote attackers to affect confidentiality and integrity of affected systems.

Refsnvd.nist.gov
Federal remediation due 2022-05-03
CVE-2012-0158
2021-11-03
Microsoft MSCOMCTL.OCX Remote Code Execution VulnerabilityRansomware
Microsoft

Microsoft MSCOMCTL.OCX contains an unspecified vulnerability that allows for remote code execution, allowing an attacker to take complete control of an affected system under the context of the current user.

CWE-94 · Code injection
Refsnvd.nist.gov
Federal remediation due 2022-05-03
CVE-2010-5326
2021-11-03
SAP NetWeaver Remote Code Execution Vulnerability
SAP

SAP NetWeaver Application Server Java Platforms Invoker Servlet does not require authentication, allowing for remote code execution via a HTTP or HTTPS request.

Refsnvd.nist.gov
Federal remediation due 2022-05-03
Prev34 / 34Next