Complete index
Zero-Day Vulnerability Archive
Search all tracked zero-day vulnerabilities and narrow the results by year, vendor, software, weakness type, or presence in the CISA and ENISA known exploited vulnerability catalogs.
| CVE | Vendor / Product | Vulnerability | CWE | Discovered | KEV |
|---|---|---|---|---|---|
| CVE-2026-42897 | MicrosoftMicrosoft Exchange Server | Stored cross-site scripting in Microsoft Exchange Server | CWE-79 | CISA KEVENISA KEV | |
| CVE-2025-27915 | Synacor Inc.Zimbra Collaboration | Stored cross-site scripting in Zimbra Collaboration | CWE-79 | CISA KEVENISA KEV | |
| CVE-2024-44309 | Apple Inc.macOS | Universal cross-site scripting in WPE WebKit and WebKitGTK+ | CWE-79 | CISA KEVENISA KEV | |
| CVE-2024-43573 | MicrosoftMicrosoft Internet Explorer | Universal cross-site scripting in Microsoft products | CWE-79 | CISA KEVENISA KEV | |
| CVE-2023-5631 | RoundcubeRoundcube Webmail | Cross-site scripting in Roundcube Webmail | CWE-79 | CISA KEVENISA KEV | |
| CVE-2023-37580 | Synacor Inc.Zimbra Collaboration | Cross-site scripting in Zimbra Collaboration | CWE-79 | CISA KEVENISA KEV | |
| CVE-2022-24682 | Synacor Inc.Zimbra Collaboration | Cross-site scripting in Zimbra Collaboration | CWE-79 | CISA KEVENISA KEV | |
| CVE-2021-1879 | Apple Inc.Apple iOS | Universal cross-site scripting in WebKitGTK+ and WPE WebKit | CWE-79 | CISA KEVENISA KEV | |
| #VU27929 | XootiXLogin/Signup Popup ( Inline Form + Woocommerce ) | Stored cross-site scripting in Login/Signup Popup ( Inline Form + Woocommerce ) | CWE-79 | — | |
| #VU25677 | Unknown | Stored cross-site scripting in Async JavaScript | CWE-79 | — | |
| #VU25676 | Unknown | Stored cross-site scripting in 10Web Google Maps - Google Maps builder Plugin | CWE-79 | — | |
| #VU25675 | Unknown | Stored cross-site scripting in Modern Events Calendar Lite | CWE-79 | — | |
| CVE-2019-9978 | Warfare PluginsWordPress Social Sharing Plugin - Social Warfare | Cross-site scripting in WordPress Social Sharing Plugin - Social Warfare | CWE-79 | CISA KEVENISA KEV | |
| CVE-2017-0210 | MicrosoftMicrosoft Internet Explorer | Cross-domain scripting in Microsoft Internet Explorer | CWE-79 | CISA KEVENISA KEV | |
| CVE-2015-1494 | FancyBoxFancyBox | Stored cross-site scripting in FancyBox | CWE-79 | — | |
| CVE-2015-0072 | MicrosoftMicrosoft Internet Explorer | Cross-site scripting in Microsoft Internet Explorer | CWE-79 | — | |
| CVE-2013-1289 | MicrosoftMicrosoft SharePoint Server | Cross-site scripting in Microsoft products | CWE-79 | — | |
| CVE-2012-2520 | MicrosoftMicrosoft Office InfoPath | Cross-site scripting in Microsoft products | CWE-79 | — | |
| CVE-2012-0767 | AdobeAdobe Flash Player | Cross-site scripting in Adobe Flash Player | CWE-79 | CISA KEVENISA KEV | |
| CVE-2011-2444 | AdobeAdobe Flash Player | Cross-site scripting in Adobe Flash Player | CWE-79 | — |
Showing 1–20 of 25 results