Complete index
Zero-Day Vulnerability Archive
Search all tracked zero-day vulnerabilities and narrow the results by year, vendor, software, weakness type, or presence in the CISA and ENISA known exploited vulnerability catalogs.
| CVE | Vendor / Product | Vulnerability | CWE | Discovered | KEV |
|---|---|---|---|---|---|
| CVE-2024-21338 | MicrosoftMicrosoft Windows | Buffer overflow in Microsoft Windows and Windows Server | CWE-119 | CISA KEVENISA KEV | |
| CVE-2024-1709 | ConnectWiseScreenConnect | Authentication bypass using an alternate path or channel in ScreenConnect | CWE-288 | CISA KEVENISA KEV | |
| CVE-2024-21410 | MicrosoftMicrosoft Exchange Server | Exposure of Resource to Wrong Sphere in Microsoft Exchange Server | CWE-668 | CISA KEVENISA KEV | |
| CVE-2024-21412 | MicrosoftMicrosoft Windows | Security features bypass in Microsoft Windows and Windows Server | CWE-254 | CISA KEVENISA KEV | |
| CVE-2024-21351 | MicrosoftMicrosoft Windows | Security features bypass in Microsoft Windows and Windows Server | CWE-254 | CISA KEVENISA KEV | |
| CVE-2024-21762 | Fortinet, IncFortiOS | Out-of-bounds write in FortiOS | CWE-787 | CISA KEVENISA KEV | |
| CVE-2024-21893 | Pulse Secure moved to IvantiIvanti Connect Secure (formerly Pulse Connect Secure) | Server-Side Request Forgery (SSRF) in Ivanti Policy Secure (formerly Pulse Policy Secure) and Ivanti Connect Secure (formerly Pulse Connect Secure) | CWE-918 | CISA KEVENISA KEV | |
| CVE-2024-23222 | Apple Inc.Apple iOS | Type confusion in WebKitGTK+ and WPE WebKit | CWE-843 | CISA KEVENISA KEV | |
| CVE-2023-6549 | CitrixCitrix NetScaler Gateway | Buffer overflow in Citrix Netscaler ADC and Citrix NetScaler Gateway | CWE-119 | CISA KEVENISA KEV | |
| CVE-2023-6548 | CitrixCitrix NetScaler Gateway | Code Injection in Citrix Netscaler ADC and Citrix NetScaler Gateway | CWE-94 | CISA KEVENISA KEV | |
| CVE-2024-0519 | GoogleGoogle Chrome | Buffer overflow in Google Chromium | CWE-119 | CISA KEVENISA KEV | |
| CVE-2024-21887 | Pulse Secure moved to IvantiIvanti Connect Secure (formerly Pulse Connect Secure) | OS Command Injection in Ivanti Policy Secure (formerly Pulse Policy Secure) and Ivanti Connect Secure (formerly Pulse Connect Secure) | CWE-78 | CISA KEVENISA KEV | |
| CVE-2023-46805 | Pulse Secure moved to IvantiIvanti Connect Secure (formerly Pulse Connect Secure) | Improper Authentication in Ivanti Policy Secure (formerly Pulse Policy Secure) and Ivanti Connect Secure (formerly Pulse Connect Secure) | CWE-287 | CISA KEVENISA KEV | |
| CVE-2023-7024 | GoogleGoogle Chrome | Heap-based buffer overflow in Google Chromium | CWE-122 | CISA KEVENISA KEV | |
| CVE-2023-47565 | QNAP Systems, Inc.QVR | OS Command Injection in QVR | CWE-78 | CISA KEVENISA KEV | |
| CVE-2023-49897 | FXCAE1021 | OS Command Injection in AE1021PE and AE1021 | CWE-78 | CISA KEVENISA KEV | |
| CVE-2023-42917 | Apple Inc.Apple iOS | Buffer overflow in WebKitGTK+ and WPE WebKit | CWE-119 | CISA KEVENISA KEV | |
| CVE-2023-42916 | Apple Inc.Apple iOS | Out-of-bounds read in WebKitGTK+ and WPE WebKit | CWE-125 | CISA KEVENISA KEV | |
| CVE-2023-6345 | GoogleGoogle Chrome | Integer overflow in Google Chromium | CWE-190 | CISA KEVENISA KEV | |
| CVE-2023-6448 | UnitronicsUnitronics Vision | Use of default credentials in Unitronics Vision | CWE-1392 | CISA KEVENISA KEV |
Showing 221–240 of 670 results