Complete index
Zero-Day Vulnerability Archive
Search all tracked zero-day vulnerabilities and narrow the results by year, vendor, software, weakness type, or presence in the CISA and ENISA known exploited vulnerability catalogs.
| CVE | Vendor / Product | Vulnerability | CWE | Discovered | KEV |
|---|---|---|---|---|---|
| CVE-2026-83549 | SonicWallSonicWall SMA 1000 | OS Command Injection in SonicWall SMA 1000 | CWE-78 | CISA KEVENISA KEV | |
| CVE-2026-83548 | SonicWallSonicWall SMA 1000 | Server-Side Request Forgery (SSRF) in SonicWall SMA 1000 | CWE-918 | CISA KEVENISA KEV | |
| CVE-2026-20349 | Cisco Systems, IncCisco Secure Firewall Adaptive Security Appliance (ASA) | Heap Inspection in Cisco Firewall Threat Defense (FTD) and Cisco Adaptive Security Appliance (ASA) | CWE-244 | CISA KEVENISA KEV | |
| CVE-2026-72898 | MetabaseMetabase | SQL injection in Metabase | CWE-89 | CISA KEVENISA KEV | |
| CVE-2026-18577 | N‑ableN-central | Authentication bypass using an alternate path or channel in N-central | CWE-288 | CISA KEVENISA KEV | |
| CVE-2026-20316 | Cisco Systems, IncCisco Secure Firewall Management Center (formerly Firepower Management Center, FMC) | Use of Hard-coded Password in Cisco Secure Firewall Management Center (formerly Firepower Management Center, FMC) | CWE-259 | CISA KEVENISA KEV | |
| CVE-2026-16232 | Check Point Software TechnologiesGaia | Improper authentication in Gaia | CWE-287 | CISA KEVENISA KEV | |
| CVE-2026-15410 | SonicWallSonicWall SMA 1000 | Code Injection in SonicWall SMA 1000 | CWE-94 | CISA KEVENISA KEV | |
| CVE-2026-15409 | SonicWallSonicWall SMA 1000 | Server-Side Request Forgery (SSRF) in SonicWall SMA 1000 | CWE-918 | CISA KEVENISA KEV | |
| CVE-2026-56164 | MicrosoftMicrosoft SharePoint Server | Missing Authentication for Critical Function in Microsoft SharePoint Server | CWE-306 | CISA KEVENISA KEV | |
| CVE-2026-56155 | MicrosoftMicrosoft Windows | Insufficient granularity of access control in Microsoft Windows and Windows Server | CWE-1220 | CISA KEVENISA KEV | |
| CVE-2026-12569 | PTCWindchill | Input validation error in Windchill and FlexPLM | CWE-20 | CISA KEVENISA KEV | |
| CVE-2026-20262 | Cisco Systems, IncCatalyst SD-WAN Manager (formerly SD-WAN vManage) | Path traversal in Catalyst SD-WAN Manager (formerly SD-WAN vManage) | CWE-22 | CISA KEVENISA KEV | |
| CVE-2026-48558 | simple-helpSimpleHelp | Improper authentication in SimpleHelp | CWE-287 | CISA KEVENISA KEV | |
| CVE-2026-35273 | OraclePeopleSoft Enterprise PeopleTools | Input validation error in PeopleSoft Enterprise PeopleTools | CWE-20 | CISA KEVENISA KEV | |
| CVE-2026-50751 | Check Point Software TechnologiesGaia | Improper authentication in Gaia | CWE-287 | CISA KEVENISA KEV | |
| CVE-2026-28318 | SolarWindsServ-U FTP Server | Improper handling of exceptional conditions in Serv-U FTP Server | CWE-755 | CISA KEVENISA KEV | |
| CVE-2026-20245 | Cisco Systems, IncCatalyst SD-WAN Manager (formerly SD-WAN vManage) | Improper Encoding or Escaping of Output in Catalyst SD-WAN Manager (formerly SD-WAN vManage) | CWE-116 | CISA KEVENISA KEV | |
| CVE-2026-54420 | LiteSpeed TechnologiesLiteSpeed User-End cPanel Plugin | Improper access control in LiteSpeed User-End cPanel Plugin and LiteSpeed WHM Plugin | CWE-284 | CISA KEVENISA KEV | |
| CVE-2025-48595 | GoogleGoogle Android | Improper input validation in Google Android | CWE-20 | CISA KEVENISA KEV |
Showing 1–20 of 670 results