Complete index
Zero-Day Vulnerability Archive
Search all tracked zero-day vulnerabilities and narrow the results by year, vendor, software, weakness type, or presence in the CISA and ENISA known exploited vulnerability catalogs.
| CVE | Vendor / Product | Vulnerability | CWE | Discovered | KEV |
|---|---|---|---|---|---|
| CVE-2026-16232 | Check Point Software TechnologiesGaia | Improper authentication in Gaia | CWE-287 | CISA KEVENISA KEV | |
| CVE-2026-48558 | simple-helpSimpleHelp | Improper authentication in SimpleHelp | CWE-287 | CISA KEVENISA KEV | |
| CVE-2026-50751 | Check Point Software TechnologiesGaia | Improper authentication in Gaia | CWE-287 | CISA KEVENISA KEV | |
| CVE-2026-20182 | Cisco Systems, IncCatalyst SD-WAN Controller (formerly SD-WAN vSmart) | Improper authentication in Cisco Systems, Inc products | CWE-287 | CISA KEVENISA KEV | |
| CVE-2026-41940 | cPanel, InccPanel | Improper authentication in cPanel | CWE-287 | CISA KEVENISA KEV | |
| CVE-2026-20127 | Cisco Systems, IncCatalyst SD-WAN Controller (formerly SD-WAN vSmart) | Improper authentication in Catalyst SD-WAN Controller (formerly SD-WAN vSmart) and Catalyst SD-WAN Manager (formerly SD-WAN vManage) | CWE-287 | CISA KEVENISA KEV | |
| CVE-2025-31201 | Apple Inc.Apple iOS | Improper authentication in Apple iOS and iPadOS | CWE-287 | CISA KEVENISA KEV | |
| CVE-2024-0012 | Palo Alto Networks, Inc.Palo Alto PAN-OS | Improper authentication in Palo Alto PAN-OS | CWE-287 | CISA KEVENISA KEV | |
| CVE-2024-49039 | MicrosoftMicrosoft Windows | Improper Authentication in Microsoft Windows and Windows Server | CWE-287 | CISA KEVENISA KEV | |
| CVE-2024-51378 | CyberPanelCyberPanel | Improper Authentication in CyberPanel | CWE-287 | CISA KEVENISA KEV | |
| CVE-2024-51567 | CyberPanelCyberPanel | Improper authentication in CyberPanel | CWE-287 | CISA KEVENISA KEV | |
| CVE-2023-46805 | Pulse Secure moved to IvantiIvanti Connect Secure (formerly Pulse Connect Secure) | Improper Authentication in Ivanti Policy Secure (formerly Pulse Policy Secure) and Ivanti Connect Secure (formerly Pulse Connect Secure) | CWE-287 | CISA KEVENISA KEV | |
| CVE-2023-22515 | AtlassianConfluence Data Center | Improper Authentication in Confluence Data Center | CWE-287 | CISA KEVENISA KEV | |
| CVE-2023-38035 | IvantiMobileIron Sentry | Improper Authentication in MobileIron Sentry | CWE-287 | CISA KEVENISA KEV | |
| CVE-2023-35078 | IvantiEndpoint Manager Mobile (formerly MobileIron Core) | Improper Authentication in Endpoint Manager Mobile (formerly MobileIron Core) | CWE-287 | CISA KEVENISA KEV | |
| CVE-2023-20867 | BroadcomVMware Tools | Improper Authentication in VMware Tools | CWE-287 | CISA KEVENISA KEV | |
| CVE-2022-48618 | Apple Inc.Apple iOS | Improper authentication in Apple iOS and iPadOS | CWE-287 | CISA KEVENISA KEV | |
| CVE-2021-22893 | Pulse Secure moved to IvantiIvanti Connect Secure (formerly Pulse Connect Secure) | Improper Authentication in Ivanti Connect Secure (formerly Pulse Connect Secure) | CWE-287 | CISA KEVENISA KEV | |
| CVE-2021-20021 | SonicWallSonicWall On-premise Email Security (ES) | Improper Authentication in SonicWall On-premise Email Security (ES) and SonicWall Hosted Email Security (HES) | CWE-287 | CISA KEVENISA KEV | |
| CVE-2021-24175 | Posimyth ThemesThe Plus Addons for Elementor Page Builder | Improper Authentication in The Plus Addons for Elementor Page Builder | CWE-287 | — |
Showing 1–20 of 25 results