Complete index
Zero-Day Vulnerability Archive
Search all tracked zero-day vulnerabilities and narrow the results by year, vendor, software, weakness type, or presence in the CISA and ENISA known exploited vulnerability catalogs.
| CVE | Vendor / Product | Vulnerability | CWE | Discovered | KEV |
|---|---|---|---|---|---|
| CVE-2024-53104 | GoogleGoogle Android | Out-of-bounds write in Linux kernel | CWE-787 | CISA KEVENISA KEV | |
| CVE-2025-0994 | TrimbleCityworks | Deserialization of Untrusted Data in Cityworks and Cityworks with office companion | CWE-502 | CISA KEVENISA KEV | |
| CVE-2024-40891 | ZyXEL Communications Corp.Zyxel CPE Series | Command Injection in Zyxel CPE Series | CWE-77 | CISA KEVENISA KEV | |
| CVE-2025-24085 | Apple Inc.Apple iOS | Use-after-free in Apple iOS and iPadOS | CWE-416 | CISA KEVENISA KEV | |
| CVE-2025-23006 | SonicWallSonicWall SMA 1000 | Deserialization of untrusted data in SonicWall SMA 1000 | CWE-502 | CISA KEVENISA KEV | |
| CVE-2025-21335 | MicrosoftMicrosoft Windows | Use-after-free in Microsoft Windows and Windows Server | CWE-416 | CISA KEVENISA KEV | |
| CVE-2025-21334 | MicrosoftMicrosoft Windows | Use-after-free in Microsoft Windows and Windows Server | CWE-416 | CISA KEVENISA KEV | |
| CVE-2025-21333 | MicrosoftMicrosoft Windows | Heap-based buffer overflow in Microsoft Windows and Windows Server | CWE-122 | CISA KEVENISA KEV | |
| CVE-2024-55591 | Fortinet, IncFortiOS | Authentication bypass using an alternate path or channel in FortiProxy and FortiOS | CWE-288 | CISA KEVENISA KEV | |
| CVE-2025-0282 | IvantiIvanti Connect Secure (formerly Pulse Connect Secure) | Stack-based buffer overflow in Ivanti Connect Secure (formerly Pulse Connect Secure) | CWE-121 | CISA KEVENISA KEV | |
| CVE-2024-3393 | Palo Alto Networks, Inc.Palo Alto PAN-OS | Improper Check for Unusual or Exceptional Conditions in Palo Alto PAN-OS | CWE-754 | CISA KEVENISA KEV | |
| CVE-2024-12356 | BeyondTrustRemote Support | OS Command Injection in Remote Support and Privileged Remote Access (PRA) | CWE-78 | CISA KEVENISA KEV | |
| CVE-2024-12686 | BeyondTrustRemote Support | OS Command Injection in Remote Support and Privileged Remote Access (PRA) | CWE-78 | CISA KEVENISA KEV | |
| CVE-2024-49138 | MicrosoftMicrosoft Windows | Heap-based buffer overflow in Microsoft Windows and Windows Server | CWE-122 | CISA KEVENISA KEV | |
| CVE-2024-55956 | CleoCleo LexiCom | Arbitrary file upload in Cleo products | CWE-434 | CISA KEVENISA KEV | |
| CVE-2024-44309 | Apple Inc.macOS | Universal cross-site scripting in WPE WebKit and WebKitGTK+ | CWE-79 | CISA KEVENISA KEV | |
| CVE-2024-44308 | Apple Inc.macOS | Input validation error in WebKitGTK+ and WPE WebKit | CWE-20 | CISA KEVENISA KEV | |
| CVE-2024-21287 | OracleOracle Agile PLM Framework | Missing Authorization in Oracle Agile PLM Framework | CWE-862 | CISA KEVENISA KEV | |
| CVE-2024-0012 | Palo Alto Networks, Inc.Palo Alto PAN-OS | Improper authentication in Palo Alto PAN-OS | CWE-287 | CISA KEVENISA KEV | |
| CVE-2024-11120 | GeoVisionGV-DSP_LPR_V3, GV-VS11, GV-VS12, GVLX 4 V2, GVLX 4 V3 | OS Command Injection in GeoVision products | CWE-78 | CISA KEVENISA KEV |
Showing 161–180 of 688 results