Complete index
Zero-Day Vulnerability Archive
Search all tracked zero-day vulnerabilities and narrow the results by year, vendor, software, weakness type, or presence in the CISA and ENISA known exploited vulnerability catalogs.
| CVE | Vendor / Product | Vulnerability | CWE | Discovered | KEV |
|---|---|---|---|---|---|
| CVE-2025-48572 | GoogleGoogle Android | Improper input validation in Google Android | CWE-20 | CISA KEVENISA KEV | |
| CVE-2025-14611 | GladinetCentreStack | Use of hard-coded cryptographic key in Triofox and CentreStack | CWE-321 | CISA KEVENISA KEV | |
| CVE-2025-58034 | Fortinet, IncFortiWeb | OS Command Injection in FortiWeb | CWE-78 | CISA KEVENISA KEV | |
| CVE-2025-13223 | GoogleGoogle Chrome | Type confusion in Google Chromium | CWE-843 | CISA KEVENISA KEV | |
| CVE-2025-64446 | Fortinet, IncFortiWeb | Path traversal in FortiWeb | CWE-22 | CISA KEVENISA KEV | |
| CVE-2025-62215 | MicrosoftMicrosoft Windows | Race condition in Microsoft Windows and Windows Server | CWE-362 | CISA KEVENISA KEV | |
| CVE-2025-61932 | MOTEX Inc.Lanscope Endpoint Manager (On-Premises) | Improper Verification of Source of a Communication Channel in Lanscope Endpoint Manager (On-Premises) | CWE-940 | CISA KEVENISA KEV | |
| CVE-2025-47827 | MicrosoftMicrosoft Windows | Improper verification of cryptographic signature in IGEL OS | CWE-347 | CISA KEVENISA KEV | |
| CVE-2025-59230 | MicrosoftMicrosoft Windows | Improper access control in Microsoft Windows and Windows Server | CWE-284 | CISA KEVENISA KEV | |
| CVE-2025-24990 | MicrosoftMicrosoft Windows | Untrusted pointer dereference in Microsoft Windows and Windows Server | CWE-822 | CISA KEVENISA KEV | |
| CVE-2025-61884 | OracleOracle E-Business Suite | Server-Side Request Forgery (SSRF) in Oracle Configurator and Oracle E-Business Suite | CWE-918 | CISA KEVENISA KEV | |
| CVE-2025-41244 | BroadcomVMware Tools | Improper access control in VMware Tools | CWE-284 | CISA KEVENISA KEV | |
| CVE-2025-11371 | GladinetCentreStack | Path traversal in CentreStack | CWE-22 | CISA KEVENISA KEV | |
| CVE-2025-20362 | Cisco Systems, IncCisco Secure Firewall Adaptive Security Appliance (ASA) | Missing authorization in Cisco Adaptive Security Appliance (ASA) and Cisco Firewall Threat Defense (FTD) | CWE-862 | CISA KEVENISA KEV | |
| CVE-2025-20352 | Cisco Systems, IncCisco IOS XE | Stack-based buffer overflow in Cisco IOS XE | CWE-121 | CISA KEVENISA KEV | |
| CVE-2025-59689 | LibraesvaEmail Security Gateway | OS command injection in Email Security Gateway | CWE-78 | CISA KEVENISA KEV | |
| CVE-2025-10585 | GoogleGoogle Chrome | Type Confusion in Google Chromium | CWE-843 | CISA KEVENISA KEV | |
| CVE-2025-21043 | Unknown | Out-of-bounds write in Samsung Mobile Firmware | CWE-787 | CISA KEVENISA KEV | |
| CVE-2025-53690 | SitecoreSitecore Experience Platform | Deserialization of Untrusted Data in Sitecore products | CWE-502 | CISA KEVENISA KEV | |
| CVE-2025-48543 | GoogleGoogle Android | Improper input validation in Google Android | CWE-20 | CISA KEVENISA KEV |
Showing 81–100 of 688 results