Complete index
Zero-Day Vulnerability Archive
Search all tracked zero-day vulnerabilities and narrow the results by year, vendor, software, weakness type, or presence in the CISA and ENISA known exploited vulnerability catalogs.
| CVE | Vendor / Product | Vulnerability | CWE | Discovered | KEV |
|---|---|---|---|---|---|
| CVE-2023-38198 | Neilpang (neil)acme.sh | OS Command Injection in acme.sh | CWE-78 | — | |
| #VU76737 | GIGABYTE GlobalUEFI firmware | Embedded malicious code (backdoor) in GIGABYTE Global products | CWE-506 | — | |
| #VU76599 | MediaBrowserEmby Server | Missing Authorization in Emby Server | CWE-862 | — | |
| CVE-2023-24932 | MicrosoftMicrosoft Windows | Security features bypass in Microsoft Windows and Windows Server | CWE-254 | — | |
| CVE-2023-29059 | 3CXElectron Mac App, Electron Windows App | Embedded malicious code (backdoor) in Electron Mac App and Electron Windows App | CWE-506 | — | |
| CVE-2023-45797 | Dream SecurityMagicLine4NX | Buffer overflow in MagicLine4NX | CWE-119 | — | |
| CVE-2023-28725 | General BytesCrypto Application Server (CAS) | Improper access control in Crypto Application Server (CAS) | CWE-284 | — | |
| CVE-2022-42458 | ShiftTech Inc.bingo!CMS | Missing Authorization in bingo!CMS | CWE-862 | — | |
| CVE-2022-3180 | WPGatewayWPGateway | Improper Authorization in WPGateway | CWE-285 | — | |
| CVE-2022-31474 | iThemesBackupBuddy | Improper Authorization in BackupBuddy | CWE-285 | — | |
| CVE-2022-4980 | General BytesCrypto Application Server (CAS) | Improper access control in Crypto Application Server (CAS) | CWE-284 | — | |
| CVE-2021-45461 | FreePBXPhone Apps | Input validation error in Phone Apps | CWE-20 | — | |
| #VU58226 | FatPipe Networks Inc.IPVPN, MPVPN, WARP | Arbitrary file upload in FatPipe Networks Inc. products | CWE-434 | — | |
| #VU57645 | EntroLinkPPX-AnyLink 6004, PPX-AnyLink 6006, PPX-AnyLink 6900, PPX-AnyLink 6900F, PPX-AnyLink 6904, PPX-AnyLink 8000 | Code Injection in EntroLink products | CWE-94 | — | |
| CVE-2021-32789 | WooCommerceWooCommerce | SQL injection in WooCommerce Blocks and WooCommerce | CWE-89 | — | |
| CVE-2021-35941 | Western DigitalWD My Book Live, WD My Book Live Duo | Improper access control in WD My Book Live and WD My Book Live Duo | CWE-284 | — | |
| CVE-2021-24370 | radykalFancy Product Designer | Arbitrary file upload in Fancy Product Designer | CWE-434 | — | |
| CVE-2021-24175 | Posimyth ThemesThe Plus Addons for Elementor Page Builder | Improper Authentication in The Plus Addons for Elementor Page Builder | CWE-287 | — | |
| #VU51219 | Super Micro Computer, Inc.X10SL7-F, X10SLA-F, X10SLH-F, X10SLL-F, X10SLL-S/-SF, X10SLL+-F, X10SLM-F, X10SLM+-F, X10SLM+-LN4F | Security restrictions bypass in Super Micro Computer, Inc. products | CWE-264 | — | |
| #VU48956 | Unknown | Embedded malicious code (backdoor) in Orion Platform | CWE-506 | — |
Showing 41–60 of 312 results