Complete index
Zero-Day Vulnerability Archive
Search all tracked zero-day vulnerabilities and narrow the results by year, vendor, software, weakness type, or presence in the CISA and ENISA known exploited vulnerability catalogs.
| CVE | Vendor / Product | Vulnerability | CWE | Discovered | KEV |
|---|---|---|---|---|---|
| CVE-2026-67276 | MikroTikMikroTik RouterOS | Improper Verification of Cryptographic Signature in MikroTik RouterOS | CWE-347 | — | |
| CVE-2026-76904 | geoserverGeoServer | SQL injection in geotools | CWE-89 | — | |
| CVE-2026-15724 | CitrixShareFile storage zones controller | Path traversal in ShareFile storage zones controller | CWE-22 | — | |
| CVE-2026-1164 | GoogleGoogle Chrome | Buffer overflow in Google Chromium | CWE-119 | — | |
| CVE-2026-5426 | Digital KnowledgeKnowledgeDeliver | Use of hard-coded credentials in KnowledgeDeliver | CWE-798 | — | |
| CVE-2026-34424 | NextendSmart Slider 3 | Embedded malicious code (backdoor) in Smart Slider 3 | CWE-506 | — | |
| #VU124720 | axiosaxios | Embedded malicious code (backdoor) in axios | CWE-506 | — | |
| CVE-2026-21992 | OracleOracle Identity Manager Connector | Missing Authentication for Critical Function in Identity Manager and Oracle Web Services Manager | CWE-306 | — | |
| CVE-2025-15556 | Notepad++Notepad++ | Improper verification of cryptographic signature in Notepad++ | CWE-347 | — | |
| CVE-2025-25256 | Fortinet, IncFortiSIEM | OS Command Injection in FortiSIEM | CWE-78 | — | |
| CVE-2025-30355 | Matrix.orgSynapse | Input validation error in Synapse | CWE-20 | — | |
| CVE-2025-9491 | MicrosoftMicrosoft Windows | Spoofing attack in Microsoft Windows and Windows Server | CWE-451 | — | |
| CVE-2025-0289 | Paragon Technologie GmbHPartition Manager | Improper access control in BioNTdrv.sys and Partition Manager | CWE-284 | — | |
| CVE-2025-1094 | PostgreSQL Global Development GroupPostgreSQL | Input validation error in PostgreSQL | CWE-20 | — | |
| CVE-2025-0626 | ContecCMS8000 Patient Monitor | Hidden functionality in CMS8000 Patient Monitor | CWE-912 | — | |
| CVE-2024-12856 | Four-FaithF3x24, F3x36 | OS Command Injection in F3x24 and F3x36 | CWE-78 | — | |
| CVE-2024-47133 | I-O DATAUD-LT1, UD-LT1/EX | OS Command Injection in UD-LT1 and UD-LT1/EX | CWE-78 | — | |
| CVE-2024-45841 | I-O DATAUD-LT1, UD-LT1/EX | Incorrect permission assignment for critical resource in UD-LT1 and UD-LT1/EX | CWE-732 | — | |
| CVE-2024-52564 | I-O DATAUD-LT1, UD-LT1/EX | Inclusion of Undocumented Features or Chicken Bits in UD-LT1 and UD-LT1/EX | CWE-1242 | — | |
| #VU100575 | Fortinet, IncFortinet FortiClient for Windows | Unprotected storage of credentials in Fortinet FortiClient for Windows | CWE-256 | — |
Showing 1–20 of 312 results