Rosetta Intel
Datasets/KEV CatalogThreat Actors
Rosetta Lab ↗Blur Horizon LLC
Datasets

KEV Catalog

CISA, queryable

Known exploited vulnerabilities as a queryable table — by CVE, vendor or product.

1676 entries·352 Ransomware·Updated 2026-08-25

1676 results·Page 5 / 34

CVE-2025-14611
2025-12-15
Gladinet CentreStack and Triofox Hard Coded Cryptographic Vulnerability
Gladinet

Gladinet CentreStack and TrioFox contain a hardcoded cryptographic keys vulnerability for their implementation of the AES cryptoscheme. This vulnerability degrades security for public exposed endpoints that may make use of it and may offer arbitrary local file inclusion when provided a specially crafted request without authentication.

CWE-798 · Hard-coded credentials
Refscentrestack.comaccess.triofox.comsupport.centrestack.comnvd.nist.gov
Federal remediation due 2026-01-05
CVE-2025-14174
2025-12-12
Google Chromium Out of Bounds Memory Access Vulnerability
Google

Google Chromium contains an out of bounds memory access vulnerability in ANGLE that could allow a remote attacker to perform out of bounds memory access via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

Refschromereleases.googleblog.comlearn.microsoft.comnvd.nist.gov
Federal remediation due 2026-01-02
CVE-2018-4063
2025-12-12
Sierra Wireless AirLink ALEOS Unrestricted Upload of File with Dangerous Type Vulnerability
Sierra Wireless

Sierra Wireless AirLink ALEOS contains an unrestricted upload of file with dangerous type vulnerability. A specially crafted HTTP request can upload a file, resulting in executable code being uploaded, and routable, to the webserver. An attacker can make an authenticated HTTP request to trigger this vulnerability. The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.

CWE-434 · Unrestricted file upload
Refscisa.govsource.sierrawireless.comsource.sierrawireless.comnvd.nist.gov
Federal remediation due 2026-01-02
CVE-2025-58360
2025-12-11
OSGeo GeoServer Improper Restriction of XML External Entity Reference Vulnerability
OSGeo

OSGeo GeoServer contains an improper restriction of XML external entity reference vulnerability that occurs when the application accepts XML input through a specific endpoint /geoserver/wms operation GetMap and could allow an attacker to define external entities within the XML request.

CWE-611
RefsThis vulnerability affects an open-source component, third-party library, or a protocol used by different products. For more information, please seeosgeo-org.atlassian.netnvd.nist.gov
Federal remediation due 2026-01-01
CVE-2025-62221
2025-12-09
Microsoft Windows Use After Free Vulnerability
Microsoft

Microsoft Windows Cloud Files Mini Filter Driver contains a use after free vulnerability that can allow an authorized attacker to elevate privileges locally.

CWE-416 · Use after free
Refsmsrc.microsoft.comnvd.nist.gov
Federal remediation due 2025-12-30
CVE-2025-6218
2025-12-09
RARLAB WinRAR Path Traversal Vulnerability
RARLAB

RARLAB WinRAR contains a path traversal vulnerability allowing an attacker to execute code in the context of the current user.

CWE-22 · Path traversal
Refswin-rar.comnvd.nist.gov
Federal remediation due 2025-12-30
CVE-2025-66644
2025-12-08
Array Networks ArrayOS AG OS Command Injection Vulnerability
Array Networks

Array Networks ArrayOS AG contains an OS command injection vulnerability that could allow an attacker to execute arbitrary commands.

CWE-78 · OS command injection
Refssupport.arraynetworks.netjpcert.or.jpnvd.nist.gov
Federal remediation due 2025-12-29
CVE-2022-37055
2025-12-08
D-Link Routers Buffer Overflow Vulnerability
D-Link

D-Link Routers contains a buffer overflow vulnerability that has a high impact on confidentiality, integrity, and availability. The impacted products could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.

CWE-120 · Classic buffer overflow
Refssupportannouncement.us.dlink.comnvd.nist.gov
Federal remediation due 2025-12-29
CVE-2025-55182
2025-12-05
Meta React Server Components Remote Code Execution VulnerabilityRansomware
Meta

Meta React Server Components contains a remote code execution vulnerability that could allow unauthenticated remote code execution by exploiting a flaw in how React decodes payloads sent to React Server Function endpoints. Please note CVE-2025-66478 has been rejected, but it is associated with CVE-2025- 55182.

RefsCheck for signs of potential compromise on all internet accessible REACT instances after applying mitigations. For more information, please seegithub.comnvd.nist.gov
Federal remediation due 2025-12-12
CVE-2021-26828
2025-12-03
OpenPLC ScadaBR Unrestricted Upload of File with Dangerous Type Vulnerability
OpenPLC

OpenPLC ScadaBR contains an unrestricted upload of file with dangerous type vulnerability that allows remote authenticated users to upload and execute arbitrary JSP files via view_edit.shtm.

CWE-434 · Unrestricted file upload
RefsThis vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please seenvd.nist.gov
Federal remediation due 2025-12-24
CVE-2025-48633
2025-12-02
Android Framework Information Disclosure Vulnerability
Android

Android Framework contains an unspecified vulnerability that allows for information disclosure.

Refssource.android.comnvd.nist.gov
Federal remediation due 2025-12-23
CVE-2025-48572
2025-12-02
Android Framework Privilege Escalation Vulnerability
Android

Android Framework contains an unspecified vulnerability that allows for privilege escalation.

Refssource.android.comnvd.nist.gov
Federal remediation due 2025-12-23
CVE-2021-26829
2025-11-28
OpenPLC ScadaBR Cross-site Scripting Vulnerability
OpenPLC

OpenPLC ScadaBR contains a cross-site scripting vulnerability via system_settings.shtm.

CWE-79 · Cross-site scripting
RefsThis vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please seenvd.nist.gov
Federal remediation due 2025-12-19
CVE-2025-61757
2025-11-21
Oracle Fusion Middleware Missing Authentication for Critical Function Vulnerability
Oracle

Oracle Fusion Middleware contains a missing authentication for critical function vulnerability, allowing unauthenticated remote attackers to take over Identity Manager.

CWE-306 · Missing authentication
Refsoracle.comnvd.nist.gov
Federal remediation due 2025-12-12
CVE-2025-13223
2025-11-19
Google Chromium V8 Type Confusion Vulnerability
Google

Google Chromium V8 contains a type confusion vulnerability that allows for heap corruption.

CWE-843 · Type confusion
Refschromereleases.googleblog.comnvd.nist.gov
Federal remediation due 2025-12-10
CVE-2025-58034
2025-11-18
Fortinet FortiWeb OS Command Injection Vulnerability
Fortinet

Fortinet FortiWeb contains an OS command Injection vulnerability that may allow an authenticated attacker to execute unauthorized code on the underlying system via crafted HTTP requests or CLI commands.

CWE-78 · OS command injection
Refsfortiguard.fortinet.comnvd.nist.gov
Federal remediation due 2025-11-25
CVE-2025-64446
2025-11-14
Fortinet FortiWeb Path Traversal Vulnerability
Fortinet

Fortinet FortiWeb contains a relative path traversal vulnerability that may allow an unauthenticated attacker to execute administrative commands on the system via crafted HTTP or HTTPS requests.

CWE-23 · Relative path traversal
Refsfortiguard.comnvd.nist.gov
Federal remediation due 2025-11-21
CVE-2025-9242
2025-11-12
WatchGuard Firebox Out-of-Bounds Write Vulnerability
WatchGuard

WatchGuard Firebox contains an out-of-bounds write vulnerability in the OS iked process that may allow a remote unauthenticated attacker to execute arbitrary code.

CWE-787 · Out-of-bounds write
Refswatchguard.comnvd.nist.gov
Federal remediation due 2025-12-03
CVE-2025-62215
2025-11-12
Microsoft Windows Race Condition Vulnerability
Microsoft

Microsoft Windows Kernel contains a race condition vulnerability that allows a local attacker with low-level privileges to escalate privileges. Successful exploitation of this vulnerability could enable the attacker to gain SYSTEM-level access.

CWE-362
Refsmsrc.microsoft.comnvd.nist.gov
Federal remediation due 2025-12-03
CVE-2025-12480
2025-11-12
Gladinet Triofox Improper Access Control Vulnerability
Gladinet

Gladinet Triofox contains an improper access control vulnerability that allows access to initial setup pages even after setup is complete.

CWE-284 · Improper access control
Refsaccess.triofox.comnvd.nist.gov
Federal remediation due 2025-12-03
CVE-2025-21042
2025-11-10
Samsung Mobile Devices Out-of-Bounds Write Vulnerability
Samsung

Samsung mobile devices contain an out-of-bounds write vulnerability in libimagecodec.quram.so. This vulnerability could allow remote attackers to execute arbitrary code.

CWE-787 · Out-of-bounds write
Refssecurity.samsungmobile.comnvd.nist.gov
Federal remediation due 2025-12-01
CVE-2025-48703
2025-11-04
CWP Control Web Panel OS Command Injection Vulnerability
CWP

CWP Control Web Panel (formerly CentOS Web Panel) contains an OS command Injection vulnerability that allows unauthenticated remote code execution via shell metacharacters in the t_total parameter in a filemanager changePerm request. A valid non-root username must be known.

CWE-78 · OS command injection
Refscontrol-webpanel.comnvd.nist.gov
Federal remediation due 2025-11-25
CVE-2025-11371
2025-11-04
Gladinet CentreStack and Triofox Files or Directories Accessible to External Parties Vulnerability
Gladinet

Gladinet CentreStack and Triofox contains a files or directories accessible to external parties vulnerability that allows unintended disclosure of system files.

CWE-552
Refscentrestack.comnvd.nist.gov
Federal remediation due 2025-11-25
CVE-2025-41244
2025-10-30
Broadcom VMware Aria Operations and VMware Tools Privilege Defined with Unsafe Actions Vulnerability
Broadcom

Broadcom VMware Aria Operations and VMware Tools contain a privilege defined with unsafe actions vulnerability. A malicious local actor with non-administrative privileges having access to a VM with VMware Tools installed and managed by Aria Operations with SDMP enabled may exploit this vulnerability to escalate privileges to root on the same VM.

CWE-267
Refssupport.broadcom.comnvd.nist.gov
Federal remediation due 2025-11-20
CVE-2025-24893
2025-10-30
XWiki Platform Eval Injection Vulnerability
XWiki

XWiki Platform contains an eval injection vulnerability that could allow any guest to perform arbitrary remote code execution through a request to SolrSearch.

CWE-95
Refsgithub.comnvd.nist.gov
Federal remediation due 2025-11-20
CVE-2025-6205
2025-10-28
Dassault Systèmes DELMIA Apriso Missing Authorization Vulnerability
Dassault Systèmes

Dassault Systèmes DELMIA Apriso contains a missing authorization vulnerability that could allow an attacker to gain privileged access to the application.

CWE-862 · Missing authorization
Refs3ds.comnvd.nist.gov
Federal remediation due 2025-11-18
CVE-2025-6204
2025-10-28
Dassault Systèmes DELMIA Apriso Code Injection Vulnerability
Dassault Systèmes

Dassault Systèmes DELMIA Apriso contains a code injection vulnerability that could allow an attacker to execute arbitrary code.

CWE-94 · Code injection
Refs3ds.comnvd.nist.gov
Federal remediation due 2025-11-18
CVE-2025-59287
2025-10-24
Microsoft Windows Server Update Service (WSUS) Deserialization of Untrusted Data Vulnerability
Microsoft

Microsoft Windows Server Update Service (WSUS) contains a deserialization of untrusted data vulnerability that allows for remote code execution.

CWE-502 · Deserialization of untrusted data
Refsmsrc.microsoft.comnvd.nist.gov
Federal remediation due 2025-11-14
CVE-2025-54236
2025-10-24
Adobe Commerce and Magento Improper Input Validation Vulnerability
Adobe

Adobe Commerce and Magento Open Source contain an improper input validation vulnerability that could allow an attacker to take over customer accounts through the Commerce REST API.

CWE-20 · Improper input validation
Refsexperienceleague.adobe.comnvd.nist.gov
Federal remediation due 2025-11-14
CVE-2025-61932
2025-10-22
Motex LANSCOPE Endpoint Manager Improper Verification of Source of a Communication Channel Vulnerability
Motex

Motex LANSCOPE Endpoint Manager contains an improper verification of source of a communication channel vulnerability allowing an attacker to execute arbitrary code by sending specially crafted packets.

CWE-940
Refsmotex.co.jpnvd.nist.gov
Federal remediation due 2025-11-12
CVE-2025-61884
2025-10-20
Oracle E-Business Suite Server-Side Request Forgery (SSRF) VulnerabilityRansomware
Oracle

Oracle E-Business Suite contains a server-side request forgery (SSRF) vulnerability in the Runtime component of Oracle Configurator. This vulnerability is remotely exploitable without authentication.

CWE-918 · Server-side request forgery
Refsoracle.comnvd.nist.gov
Federal remediation due 2025-11-10
CVE-2025-33073
2025-10-20
Microsoft Windows SMB Client Improper Access Control Vulnerability
Microsoft

Microsoft Windows SMB Client contains an improper access control vulnerability that could allow for privilege escalation. An attacker could execute a specially crafted malicious script to coerce the victim machine to connect back to the attack system using SMB and authenticate.

CWE-284 · Improper access control
Refsmsrc.microsoft.comnvd.nist.gov
Federal remediation due 2025-11-10
CVE-2025-2747
2025-10-20
Kentico Xperience CMS Authentication Bypass Using an Alternate Path or Channel Vulnerability
Kentico

Kentico Xperience CMS contains an authentication bypass using an alternate path or channel vulnerability that could allow an attacker to control administrative objects.

CWE-288 · Authentication bypass
Refsdevnet.kentico.comnvd.nist.gov
Federal remediation due 2025-11-10
CVE-2025-2746
2025-10-20
Kentico Xperience CMS Authentication Bypass Using an Alternate Path or Channel Vulnerability
Kentico

Kentico Xperience CMS contains an authentication bypass using an alternate path or channel vulnerability that could allow an attacker to control administrative objects.

CWE-288 · Authentication bypass
Refsdevnet.kentico.comnvd.nist.gov
Federal remediation due 2025-11-10
CVE-2022-48503
2025-10-20
Apple Multiple Products Unspecified Vulnerability
Apple

Apple macOS, iOS, tvOS, Safari, and watchOS contain an unspecified vulnerability in JavaScriptCore that when processing web content may lead to arbitrary code execution. The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.

Refssupport.apple.comsupport.apple.comsupport.apple.comsupport.apple.comsupport.apple.comnvd.nist.gov
Federal remediation due 2025-11-10
CVE-2025-54253
2025-10-15
Adobe Experience Manager Forms Code Execution Vulnerability
Adobe / Experience Manager (AEM) Forms

Adobe Experience Manager Forms in JEE contains an unspecified vulnerability that allows for arbitrary code execution.

Refshelpx.adobe.comnvd.nist.gov
Federal remediation due 2025-11-05
CVE-2025-59230
2025-10-14
Microsoft Windows Improper Access Control Vulnerability
Microsoft

Microsoft Windows contains an improper access control vulnerability in Windows Remote Access Connection Manager which could allow an authorized attacker to elevate privileges locally.

CWE-284 · Improper access control
Refsmsrc.microsoft.comnvd.nist.gov
Federal remediation due 2025-11-04
CVE-2025-47827
2025-10-14
IGEL OS Use of a Key Past its Expiration Date Vulnerability
IGEL

IGEL OS contains a use of a key past its expiration date vulnerability that allows for Secure Boot bypass. The igel-flash-driver module improperly verifies a cryptographic signature. Ultimately, a crafted root filesystem can be mounted from an unverified SquashFS image.

CWE-324
Refsmsrc.microsoft.comnvd.nist.gov
Federal remediation due 2025-11-04
CVE-2025-24990
2025-10-14
Microsoft Windows Untrusted Pointer Dereference Vulnerability
Microsoft

Microsoft Windows Agere Modem Driver contains an untrusted pointer dereference vulnerability that allows for privilege escalation. An attacker who successfully exploited this vulnerability could gain administrator privileges.

CWE-822
Refsmsrc.microsoft.comnvd.nist.gov
Federal remediation due 2025-11-04
CVE-2016-7836
2025-10-14
SKYSEA Client View Improper Authentication Vulnerability
SKYSEA

SKYSEA Client View contains an improper authentication vulnerability that allows remote code execution via a flaw in processing authentication on the TCP connection with the management console program.

CWE-287 · Improper authentication
Refsskyseaclientview.netnvd.nist.gov
Federal remediation due 2025-11-04
CVE-2021-43798
2025-10-09
Grafana Path Traversal Vulnerability
Grafana Labs

Grafana contains a path traversal vulnerability that could allow access to local files.

CWE-22 · Path traversal
Refsgrafana.comnvd.nist.gov
Federal remediation due 2025-10-30
CVE-2025-27915
2025-10-07
Synacor Zimbra Collaboration Suite (ZCS) Cross-site Scripting Vulnerability
Synacor

Synacor Zimbra Collaboration Suite (ZCS) contains a cross-site scripting vulnerability that exists in the Classic Web Client due to insufficient sanitization of HTML content in ICS files. When a user views an e-mail message containing a malicious ICS entry, its embedded JavaScript executes via an ontoggle event inside a tag. This allows an attacker to run arbitrary JavaScript within the victim's session, potentially leading to unauthorized actions such as setting e-mail filters to redirect messages to an attacker-controlled address. As a result, an attacker can perform unauthorized actions on the victim's account, including e-mail redirection and data exfiltration.

CWE-79 · Cross-site scripting
Refswiki.zimbra.comnvd.nist.gov
Federal remediation due 2025-10-28
CVE-2025-61882
2025-10-06
Oracle E-Business Suite Unspecified VulnerabilityRansomware
Oracle

Oracle E-Business Suite contains an unspecified vulnerability in the BI Publisher Integration component. The vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Concurrent Processing. Successful attacks can result in takeover of Oracle Concurrent Processing.

Refsoracle.comnvd.nist.gov
Federal remediation due 2025-10-27
CVE-2021-43226
2025-10-06
Microsoft Windows Privilege Escalation VulnerabilityRansomware
Microsoft

Microsoft Windows Common Log File System Driver contains a privilege escalation vulnerability that could allow a local, privileged attacker to bypass certain security mechanisms.

Refsmsrc.microsoft.comnvd.nist.gov
Federal remediation due 2025-10-27
CVE-2021-22555
2025-10-06
Linux Kernel Heap Out-of-Bounds Write Vulnerability
Linux

Linux Kernel contains a heap out-of-bounds write vulnerability that could allow an attacker to gain privileges or cause a DoS (via heap memory corruption) through user name space.

CWE-787 · Out-of-bounds write
Refsgit.kernel.orggit.kernel.orgsecurity.netapp.comgithub.comnvd.nist.gov
Federal remediation due 2025-10-27
CVE-2013-3918
2025-10-06
Microsoft Windows Out-of-Bounds Write Vulnerability
Microsoft

Microsoft Windows contains an out-of-bounds write vulnerability in the InformationCardSigninHelper Class ActiveX control, icardie.dll. An attacker could exploit the vulnerability by constructing a specially crafted webpage. When a user views the webpage, the vulnerability could allow remote code execution. An attacker who successfully exploited this vulnerability could gain the same user rights as the current user. The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.

Refsdocs.microsoft.comnvd.nist.gov
Federal remediation due 2025-10-27
CVE-2011-3402
2025-10-06
Microsoft Windows Remote Code Execution Vulnerability
Microsoft

Microsoft Windows Kernel contains an unspecified vulnerability in the TrueType font parsing engine in win32k.sys in the kernel-mode drivers that allows remote attackers to execute arbitrary code via crafted font data in a Word document or web page.

Refsdocs.microsoft.comnvd.nist.gov
Federal remediation due 2025-10-27
CVE-2010-3962
2025-10-06
Microsoft Internet Explorer Uninitialized Memory Corruption Vulnerability
Microsoft

Microsoft Internet Explorer contains an uninitialized memory corruption vulnerability that could allow for remote code execution. The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.

Refslearn.microsoft.comnvd.nist.gov
Federal remediation due 2025-10-27
CVE-2010-3765
2025-10-06
Mozilla Multiple Products Remote Code Execution Vulnerability
Mozilla

Mozilla Firefox, SeaMonkey, and Thunderbird contain an unspecified vulnerability when JavaScript is enabled. This allows remote attackers to execute arbitrary code via vectors related to nsCSSFrameConstructor::ContentAppended, the appendChild method, incorrect index tracking, and the creation of multiple frames, which triggers memory corruption.

Refsmozilla.orgnvd.nist.gov
Federal remediation due 2025-10-27
CVE-2025-4008
2025-10-02
Smartbedded Meteobridge Command Injection Vulnerability
Smartbedded

Smartbedded Meteobridge contains a command injection vulnerability that could allow remote unauthenticated attackers to gain arbitrary command execution with elevated privileges (root) on affected devices.

CWE-306 · Missing authenticationCWE-77 · Command injection
Refsforum.meteohub.denvd.nist.gov
Federal remediation due 2025-10-23
Prev5 / 34Next