Complete index
Zero-Day Vulnerability Archive
Search all tracked zero-day vulnerabilities and narrow the results by year, vendor, software, weakness type, or presence in the CISA and ENISA known exploited vulnerability catalogs.
| CVE | Vendor / Product | Vulnerability | CWE | Discovered | KEV |
|---|---|---|---|---|---|
| CVE-2026-48172 | LiteSpeed TechnologiesLiteSpeed User-End cPanel Plugin | Incorrect Privilege Assignment in LiteSpeed User-End cPanel Plugin and LiteSpeed WHM Plugin | CWE-266 | CISA KEVENISA KEV | |
| CVE-2026-34926 | Trend MicroApex One | Relative Path Traversal in Apex One | CWE-23 | CISA KEVENISA KEV | |
| CVE-2026-45321 | TanStackarktype-adapter | Embedded malicious code in TanStack products | CWE-506 | CISA KEVENISA KEV | |
| CVE-2026-48027 | NxNx Console VSCode Extension | Embedded malicious code in Nx Console VSCode Extension | CWE-506 | CISA KEVENISA KEV | |
| CVE-2026-45498 | MicrosoftWindows Defender | Input validation error in Windows Defender | CWE-20 | CISA KEVENISA KEV | |
| CVE-2026-41091 | MicrosoftMicrosoft Malware Protection Engine | Link following in Microsoft Malware Protection Engine | CWE-59 | CISA KEVENISA KEV | |
| CVE-2026-42897 | MicrosoftMicrosoft Exchange Server | Stored cross-site scripting in Microsoft Exchange Server | CWE-79 | CISA KEVENISA KEV | |
| CVE-2026-20182 | Cisco Systems, IncCatalyst SD-WAN Controller (formerly SD-WAN vSmart) | Improper authentication in Cisco Systems, Inc products | CWE-287 | CISA KEVENISA KEV | |
| CVE-2026-6973 | IvantiEndpoint Manager Mobile (formerly MobileIron Core) | Input validation error in Endpoint Manager Mobile (formerly MobileIron Core) | CWE-20 | CISA KEVENISA KEV | |
| CVE-2026-8398 | Disk Soft LtdDaemon Tools | Embedded malicious code (backdoor) in Daemon Tools | CWE-506 | CISA KEVENISA KEV | |
| CVE-2026-0300 | Palo Alto Networks, Inc.Palo Alto PAN-OS | Out-of-bounds write in Palo Alto PAN-OS | CWE-787 | CISA KEVENISA KEV | |
| CVE-2026-7473 | Arista NetworksArista Extensible Operating System (EOS) | Incomplete Comparison with Missing Factors in Arista Extensible Operating System (EOS) | CWE-1023 | CISA KEVENISA KEV | |
| CVE-2026-41940 | cPanel, InccPanel | Improper authentication in cPanel | CWE-287 | CISA KEVENISA KEV | |
| CVE-2026-33825 | MicrosoftWindows Defender | Insufficient Granularity of Access Control in Windows Defender | CWE-1220 | CISA KEVENISA KEV | |
| CVE-2026-32201 | MicrosoftMicrosoft SharePoint Server | Input validation error in Microsoft SharePoint Server | CWE-20 | CISA KEVENISA KEV | |
| CVE-2026-34621 | AdobeAdobe Acrobat | Prototype pollution in Adobe Reader and Adobe Acrobat | CWE-1321 | CISA KEVENISA KEV | |
| CVE-2026-35616 | Fortinet, IncFortiClientEMS | Missing authorization in FortiClientEMS | CWE-862 | CISA KEVENISA KEV | |
| CVE-2026-5281 | GoogleGoogle Chrome | Use-after-free in Google Chromium | CWE-416 | CISA KEVENISA KEV | |
| CVE-2026-3502 | TrueConfTrueConf client for Windows | Download of code without integrity check in TrueConf client for Windows | CWE-494 | CISA KEVENISA KEV | |
| CVE-2026-33634 | Aqua Securitytrivy | Embedded malicious code (backdoor) in Aqua Security products | CWE-506 | CISA KEVENISA KEV |
Showing 21–40 of 670 results