Complete index
Zero-Day Vulnerability Archive
Search all tracked zero-day vulnerabilities and narrow the results by year, vendor, software, weakness type, or presence in the CISA and ENISA known exploited vulnerability catalogs.
| CVE | Vendor / Product | Vulnerability | CWE | Discovered | KEV |
|---|---|---|---|---|---|
| CVE-2026-83549 | SonicWallSonicWall SMA 1000 | OS Command Injection in SonicWall SMA 1000 | CWE-78 | CISA KEVENISA KEV | |
| CVE-2025-58034 | Fortinet, IncFortiWeb | OS Command Injection in FortiWeb | CWE-78 | CISA KEVENISA KEV | |
| CVE-2025-59689 | LibraesvaEmail Security Gateway | OS command injection in Email Security Gateway | CWE-78 | CISA KEVENISA KEV | |
| CVE-2025-25256 | Fortinet, IncFortiSIEM | OS Command Injection in FortiSIEM | CWE-78 | — | |
| CVE-2025-54948 | Trend MicroApex One | OS Command Injection in Apex One | CWE-78 | CISA KEVENISA KEV | |
| CVE-2024-12856 | Four-FaithF3x24, F3x36 | OS Command Injection in F3x24 and F3x36 | CWE-78 | — | |
| CVE-2024-12356 | BeyondTrustRemote Support | OS Command Injection in Remote Support and Privileged Remote Access (PRA) | CWE-78 | CISA KEVENISA KEV | |
| CVE-2024-12686 | BeyondTrustRemote Support | OS Command Injection in Remote Support and Privileged Remote Access (PRA) | CWE-78 | CISA KEVENISA KEV | |
| CVE-2024-47133 | I-O DATAUD-LT1, UD-LT1/EX | OS Command Injection in UD-LT1 and UD-LT1/EX | CWE-78 | — | |
| CVE-2024-11120 | GeoVisionGV-DSP_LPR_V3, GV-VS11, GV-VS12, GVLX 4 V2, GVLX 4 V3 | OS Command Injection in GeoVision products | CWE-78 | CISA KEVENISA KEV | |
| CVE-2024-9474 | Palo Alto Networks, Inc.Palo Alto PAN-OS | OS Command Injection in Palo Alto PAN-OS | CWE-78 | CISA KEVENISA KEV | |
| CVE-2024-9380 | IvantiIvanti Cloud Services Appliance (CSA) | OS Command Injection in Ivanti Cloud Services Appliance (CSA) | CWE-78 | CISA KEVENISA KEV | |
| CVE-2024-20399 | Cisco Systems, IncCisco NX-OS | OS Command Injection in Cisco NX-OS | CWE-78 | CISA KEVENISA KEV | |
| CVE-2023-50358 | QNAP Systems, Inc.QNAP QTS | OS Command Injection in QuTS hero and QNAP QTS | CWE-78 | — | |
| CVE-2024-21887 | Pulse Secure moved to IvantiIvanti Connect Secure (formerly Pulse Connect Secure) | OS Command Injection in Ivanti Policy Secure (formerly Pulse Policy Secure) and Ivanti Connect Secure (formerly Pulse Connect Secure) | CWE-78 | CISA KEVENISA KEV | |
| CVE-2023-47565 | QNAP Systems, Inc.QVR | OS Command Injection in QVR | CWE-78 | CISA KEVENISA KEV | |
| CVE-2023-49897 | FXCAE1021 | OS Command Injection in AE1021PE and AE1021 | CWE-78 | CISA KEVENISA KEV | |
| CVE-2023-41179 | Trend MicroApex One | OS Command Injection in Worry-Free Business Security and Apex One | CWE-78 | CISA KEVENISA KEV | |
| CVE-2023-38198 | Neilpang (neil)acme.sh | OS Command Injection in acme.sh | CWE-78 | — | |
| CVE-2023-2868 | Barracuda NetworksEmail Security Gateway (ESG) | OS Command Injection in Email Security Gateway (ESG) | CWE-78 | CISA KEVENISA KEV |
Showing 1–20 of 26 results