Complete index
Zero-Day Vulnerability Archive
Search all tracked zero-day vulnerabilities and narrow the results by year, vendor, software, weakness type, or presence in the CISA and ENISA known exploited vulnerability catalogs.
| CVE | Vendor / Product | Vulnerability | CWE | Discovered | KEV |
|---|---|---|---|---|---|
| CVE-2026-3910 | GoogleGoogle Chrome | Improperly implemented security check for standard in Google Chromium | CWE-358 | CISA KEVENISA KEV | |
| CVE-2026-3909 | GoogleGoogle Chrome | Out-of-bounds write in Google Chromium | CWE-787 | CISA KEVENISA KEV | |
| CVE-2026-21385 | GoogleGoogle Android | Integer overflow in Qualcomm products | CWE-190 | CISA KEVENISA KEV | |
| CVE-2026-20127 | Cisco Systems, IncCatalyst SD-WAN Controller (formerly SD-WAN vSmart) | Improper authentication in Catalyst SD-WAN Controller (formerly SD-WAN vSmart) and Catalyst SD-WAN Manager (formerly SD-WAN vManage) | CWE-287 | CISA KEVENISA KEV | |
| CVE-2026-20700 | Apple Inc.macOS | Buffer overflow in macOS | CWE-119 | CISA KEVENISA KEV | |
| CVE-2026-21519 | MicrosoftMicrosoft Windows | Type Confusion in Microsoft Windows and Windows Server | CWE-843 | CISA KEVENISA KEV | |
| CVE-2026-21525 | MicrosoftWindows Server | NULL pointer dereference in Microsoft Windows and Windows Server | CWE-476 | CISA KEVENISA KEV | |
| CVE-2026-21533 | MicrosoftWindows Server | Improper privilege management in Microsoft Windows and Windows Server | CWE-269 | CISA KEVENISA KEV | |
| CVE-2026-21513 | MicrosoftMicrosoft Windows | Protection Mechanism Failure in Microsoft products | CWE-693 | CISA KEVENISA KEV | |
| CVE-2026-21510 | MicrosoftMicrosoft Windows | Protection Mechanism Failure in Microsoft Windows and Windows Server | CWE-693 | CISA KEVENISA KEV | |
| CVE-2026-21514 | MicrosoftMicrosoft Office | Reliance on Untrusted Inputs in a Security Decision in Microsoft products | CWE-807 | CISA KEVENISA KEV | |
| CVE-2025-68686 | Fortinet, IncFortiOS | Information disclosure in FortiOS | CWE-200 | CISA KEVENISA KEV | |
| CVE-2026-1340 | IvantiEndpoint Manager Mobile (formerly MobileIron Core) | Code Injection in Endpoint Manager Mobile (formerly MobileIron Core) | CWE-94 | CISA KEVENISA KEV | |
| CVE-2026-21509 | MicrosoftMicrosoft Office | Reliance on Untrusted Inputs in a Security Decision in Microsoft Office | CWE-807 | CISA KEVENISA KEV | |
| CVE-2026-24858 | Fortinet, IncFortiOS | Improper verification of cryptographic signature in Fortinet, Inc products | CWE-347 | CISA KEVENISA KEV | |
| CVE-2026-20805 | MicrosoftMicrosoft Windows | Information disclosure in Microsoft Windows and Windows Server | CWE-200 | CISA KEVENISA KEV | |
| CVE-2025-14733 | WatchGuardFireware OS | Out-of-bounds write in Fireware OS | CWE-787 | CISA KEVENISA KEV | |
| CVE-2025-20393 | Cisco Systems, IncSecure Email Gateway | Input validation error in Cisco Secure Email and Web Manager and Secure Email Gateway | CWE-20 | CISA KEVENISA KEV | |
| CVE-2025-40602 | SonicWallSonicWall SMA 1000 | Missing authorization in SonicWall SMA 1000 | CWE-862 | CISA KEVENISA KEV | |
| CVE-2025-43529 | Apple Inc.Apple iOS | Use-after-free in WebKitGTK+ and WPE WebKit | CWE-416 | CISA KEVENISA KEV |
Showing 41–60 of 670 results