Complete index
Zero-Day Vulnerability Archive
Search all tracked zero-day vulnerabilities and narrow the results by year, vendor, software, weakness type, or presence in the CISA and ENISA known exploited vulnerability catalogs.
| CVE | Vendor / Product | Vulnerability | CWE | Discovered | KEV |
|---|---|---|---|---|---|
| CVE-2026-15409 | SonicWallSonicWall SMA 1000 | Server-Side Request Forgery (SSRF) in SonicWall SMA 1000 | CWE-918 | CISA KEVENISA KEV | |
| CVE-2026-56164 | MicrosoftMicrosoft SharePoint Server | Missing Authentication for Critical Function in Microsoft SharePoint Server | CWE-306 | CISA KEVENISA KEV | |
| CVE-2026-56155 | MicrosoftMicrosoft Windows | Insufficient granularity of access control in Microsoft Windows and Windows Server | CWE-1220 | CISA KEVENISA KEV | |
| CVE-2026-12569 | PTCWindchill | Input validation error in Windchill and FlexPLM | CWE-20 | CISA KEVENISA KEV | |
| CVE-2026-20262 | Cisco Systems, IncCatalyst SD-WAN Manager (formerly SD-WAN vManage) | Path traversal in Catalyst SD-WAN Manager (formerly SD-WAN vManage) | CWE-22 | CISA KEVENISA KEV | |
| CVE-2026-48558 | simple-helpSimpleHelp | Improper authentication in SimpleHelp | CWE-287 | CISA KEVENISA KEV | |
| CVE-2026-35273 | OraclePeopleSoft Enterprise PeopleTools | Input validation error in PeopleSoft Enterprise PeopleTools | CWE-20 | CISA KEVENISA KEV | |
| CVE-2026-50751 | Check Point Software TechnologiesGaia | Improper authentication in Gaia | CWE-287 | CISA KEVENISA KEV | |
| CVE-2026-28318 | SolarWindsServ-U FTP Server | Improper handling of exceptional conditions in Serv-U FTP Server | CWE-755 | CISA KEVENISA KEV | |
| CVE-2026-20245 | Cisco Systems, IncCatalyst SD-WAN Manager (formerly SD-WAN vManage) | Improper Encoding or Escaping of Output in Catalyst SD-WAN Manager (formerly SD-WAN vManage) | CWE-116 | CISA KEVENISA KEV | |
| CVE-2026-54420 | LiteSpeed TechnologiesLiteSpeed User-End cPanel Plugin | Improper access control in LiteSpeed User-End cPanel Plugin and LiteSpeed WHM Plugin | CWE-284 | CISA KEVENISA KEV | |
| CVE-2025-48595 | GoogleGoogle Android | Improper input validation in Google Android | CWE-20 | CISA KEVENISA KEV | |
| CVE-2026-48172 | LiteSpeed TechnologiesLiteSpeed User-End cPanel Plugin | Incorrect Privilege Assignment in LiteSpeed User-End cPanel Plugin and LiteSpeed WHM Plugin | CWE-266 | CISA KEVENISA KEV | |
| CVE-2026-34926 | Trend MicroApex One | Relative Path Traversal in Apex One | CWE-23 | CISA KEVENISA KEV | |
| CVE-2026-45321 | TanStackarktype-adapter | Embedded malicious code in TanStack products | CWE-506 | CISA KEVENISA KEV | |
| CVE-2026-48027 | NxNx Console VSCode Extension | Embedded malicious code in Nx Console VSCode Extension | CWE-506 | CISA KEVENISA KEV | |
| CVE-2026-45498 | MicrosoftWindows Defender | Input validation error in Windows Defender | CWE-20 | CISA KEVENISA KEV | |
| CVE-2026-41091 | MicrosoftMicrosoft Malware Protection Engine | Link following in Microsoft Malware Protection Engine | CWE-59 | CISA KEVENISA KEV | |
| CVE-2026-42897 | MicrosoftMicrosoft Exchange Server | Stored cross-site scripting in Microsoft Exchange Server | CWE-79 | CISA KEVENISA KEV | |
| CVE-2026-20182 | Cisco Systems, IncCatalyst SD-WAN Controller (formerly SD-WAN vSmart) | Improper authentication in Cisco Systems, Inc products | CWE-287 | CISA KEVENISA KEV |
Showing 21–40 of 688 results