Complete index
Zero-Day Vulnerability Archive
Search all tracked zero-day vulnerabilities and narrow the results by year, vendor, software, weakness type, or presence in the CISA and ENISA known exploited vulnerability catalogs.
| CVE | Vendor / Product | Vulnerability | CWE | Discovered | KEV |
|---|---|---|---|---|---|
| CVE-2026-58704 | GooglePixel | Improper input validation in Pixel | CWE-20 | CISA KEV | |
| CVE-2026-76460 | Cisco Systems, IncCisco Identity Services Engine (ISE) | Incorrect use of privileged APIs in Cisco Identity Services Engine (ISE) | CWE-648 | CISA KEV | |
| CVE-2026-87886 | AcronisAcronis Backup plugin for cPanel & WHM for Linux | Incorrect default permissions in Acronis Backup extension for Plesk for Linux and Acronis Backup plugin for cPanel & WHM for Linux | CWE-276 | CISA KEV | |
| CVE-2026-76461 | Cisco Systems, IncSecure Email Gateway | SQL injection in Secure Email Gateway | CWE-89 | CISA KEV | |
| CVE-2026-87491 | GoogleGoogle Chrome | Out-of-bounds write in Google Chromium | CWE-787 | CISA KEV | |
| CVE-2026-85880 | MicrosoftMicrosoft Windows | Heap-based buffer overflow in Microsoft Windows and Windows Server | CWE-122 | CISA KEV | |
| CVE-2026-81963 | MicrosoftMicrosoft Windows | Insecure link following in Microsoft Windows and Windows Server | CWE-59 | CISA KEV | |
| CVE-2026-75650 | AdobeAdobe Commerce (formerly Magento Commerce) | Template injection in Adobe products | CWE-1336 | CISA KEV | |
| CVE-2026-85046 | GoogleGoogle Chrome | Type Confusion in Google Chromium | CWE-843 | CISA KEV | |
| CVE-2026-67276 | MikroTikMikroTik RouterOS | Improper Verification of Cryptographic Signature in MikroTik RouterOS | CWE-347 | — | |
| CVE-2026-83549 | SonicWallSonicWall SMA 1000 | OS Command Injection in SonicWall SMA 1000 | CWE-78 | CISA KEVENISA KEV | |
| CVE-2026-83548 | SonicWallSonicWall SMA 1000 | Server-Side Request Forgery (SSRF) in SonicWall SMA 1000 | CWE-918 | CISA KEVENISA KEV | |
| CVE-2026-81578 | PaperCut SoftwarePaperCut NG | Missing authentication for critical function in PaperCut MF and PaperCut NG | CWE-306 | CISA KEV | |
| CVE-2026-82078 | PaperCut SoftwarePaperCut NG | Unsafe reflection in PaperCut MF and PaperCut NG | CWE-470 | CISA KEV | |
| CVE-2026-76904 | geoserverGeoServer | SQL injection in geotools | CWE-89 | — | |
| CVE-2026-20349 | Cisco Systems, IncCisco Secure Firewall Adaptive Security Appliance (ASA) | Heap Inspection in Cisco Firewall Threat Defense (FTD) and Cisco Adaptive Security Appliance (ASA) | CWE-244 | CISA KEVENISA KEV | |
| CVE-2026-68820 | MicrosoftMicrosoft Windows | Use-after-free in Microsoft Windows and Windows Server | CWE-416 | CISA KEV | |
| CVE-2026-72898 | MetabaseMetabase | SQL injection in Metabase | CWE-89 | CISA KEVENISA KEV | |
| CVE-2026-18577 | N‑ableN-central | Authentication bypass using an alternate path or channel in N-central | CWE-288 | CISA KEVENISA KEV | |
| CVE-2026-20316 | Cisco Systems, IncCisco Secure Firewall Management Center (formerly Firepower Management Center, FMC) | Use of Hard-coded Password in Cisco Secure Firewall Management Center (formerly Firepower Management Center, FMC) | CWE-259 | CISA KEVENISA KEV |
Showing 1–20 of 1,000 results