Complete index
Zero-Day Vulnerability Archive
Search all tracked zero-day vulnerabilities and narrow the results by year, vendor, software, weakness type, or presence in the CISA and ENISA known exploited vulnerability catalogs.
| CVE | Vendor / Product | Vulnerability | CWE | Discovered | KEV |
|---|---|---|---|---|---|
| CVE-2025-4664 | GoogleGoogle Chrome | Permissions, Privileges, and Access Controls in Google Chromium | CWE-264 | CISA KEVENISA KEV | |
| CVE-2025-4428 | IvantiEndpoint Manager Mobile (formerly MobileIron Core) | Code Injection in Endpoint Manager Mobile (formerly MobileIron Core) | CWE-94 | CISA KEVENISA KEV | |
| CVE-2025-32756 | Fortinet, IncFortiVoice | Stack-based buffer overflow in Fortinet, Inc products | CWE-121 | CISA KEVENISA KEV | |
| CVE-2025-32706 | MicrosoftMicrosoft Windows | Input validation error in Microsoft Windows and Windows Server | CWE-20 | CISA KEVENISA KEV | |
| CVE-2025-32709 | MicrosoftMicrosoft Windows | Use-after-free in Microsoft Windows and Windows Server | CWE-416 | CISA KEVENISA KEV | |
| CVE-2025-30400 | MicrosoftMicrosoft Windows | Use-after-free in Microsoft Windows and Windows Server | CWE-416 | CISA KEVENISA KEV | |
| CVE-2025-30397 | MicrosoftMicrosoft Internet Explorer | Type confusion in Microsoft products | CWE-843 | CISA KEVENISA KEV | |
| CVE-2025-32701 | MicrosoftMicrosoft Windows | Use-after-free in Microsoft Windows and Windows Server | CWE-416 | CISA KEVENISA KEV | |
| CVE-2025-4427 | IvantiEndpoint Manager Mobile (formerly MobileIron Core) | Authentication bypass using an alternate path or channel in Endpoint Manager Mobile (formerly MobileIron Core) | CWE-288 | CISA KEVENISA KEV | |
| CVE-2025-31324 | SAPSAP NetWeaver | Arbitrary file upload in SAP NetWeaver | CWE-434 | CISA KEVENISA KEV | |
| CVE-2025-42599 | QUALITIA CO., LTD.Active! mail | Stack-based buffer overflow in Active! mail | CWE-121 | CISA KEVENISA KEV | |
| CVE-2025-1976 | BrocadeBrocade Fabric OS | Code Injection in Brocade Fabric OS | CWE-94 | CISA KEVENISA KEV | |
| CVE-2025-31201 | Apple Inc.Apple iOS | Improper authentication in Apple iOS and iPadOS | CWE-287 | CISA KEVENISA KEV | |
| CVE-2025-31200 | Apple Inc.Apple iOS | Buffer overflow in Apple iOS and iPadOS | CWE-119 | CISA KEVENISA KEV | |
| CVE-2025-29824 | MicrosoftMicrosoft Windows | Use-after-free in Microsoft Windows and Windows Server | CWE-416 | CISA KEVENISA KEV | |
| CVE-2025-3928 | CommvaultCommvault | Input validation error in Commvault | CWE-20 | CISA KEVENISA KEV | |
| CVE-2025-22457 | IvantiIvanti Connect Secure (formerly Pulse Connect Secure) | Stack-based buffer overflow in Ivanti Connect Secure (formerly Pulse Connect Secure) | CWE-121 | CISA KEVENISA KEV | |
| CVE-2025-21042 | SamsungSamsung Mobile Firmware | Out-of-bounds write in Samsung Mobile Firmware | CWE-787 | CISA KEVENISA KEV | |
| CVE-2025-27915 | Synacor Inc.Zimbra Collaboration | Stored cross-site scripting in Zimbra Collaboration | CWE-79 | CISA KEVENISA KEV | |
| CVE-2025-2783 | GoogleGoogle Chrome | Input validation error in Google Chromium | CWE-20 | CISA KEVENISA KEV |
Showing 101–120 of 670 results