Complete index
Zero-Day Vulnerability Archive
Search all tracked zero-day vulnerabilities and narrow the results by year, vendor, software, weakness type, or presence in the CISA and ENISA known exploited vulnerability catalogs.
| CVE | Vendor / Product | Vulnerability | CWE | Discovered | KEV |
|---|---|---|---|---|---|
| #VU48952 | wpecommerce, alexanderfoxcEasy WP SMTP | Improper access control in Easy WP SMTP | CWE-284 | — | |
| #VU27929 | XootiXLogin/Signup Popup ( Inline Form + Woocommerce ) | Stored cross-site scripting in Login/Signup Popup ( Inline Form + Woocommerce ) | CWE-79 | — | |
| #VU27672 | ElementorElementor Pro | Arbitrary file upload in Elementor Pro | CWE-434 | — | |
| #VU27193 | Apple Inc.Apple iOS | Out-of-bounds write in Apple iOS | CWE-787 | — | |
| #VU26285 | Merit LILIN Ent. Co., Ltd.DHD204, DHD204A, DHD208, DHD208A, DHD216, DHD216A, DHD304A, DHD308A, DHD316A, DHD504A, DHD508A, DHD516A | Use of hard-coded credentials in Merit LILIN Ent. Co., Ltd. products | CWE-798 | — | |
| #VU25822 | Unknown | Improper access control in Custom Searchable Data Entry System | CWE-284 | — | |
| #VU25677 | Unknown | Stored cross-site scripting in Async JavaScript | CWE-79 | — | |
| #VU25676 | Unknown | Stored cross-site scripting in 10Web Google Maps - Google Maps builder Plugin | CWE-79 | — | |
| #VU25675 | Unknown | Stored cross-site scripting in Modern Events Calendar Lite | CWE-79 | — | |
| #VU25627 | Unknown | Improper access control in Flexible Checkout Fields for WooCommerce | CWE-284 | — | |
| CVE-2019-2729 | OracleOracle WebLogic Server | Deserialization of Untrusted Data in Oracle WebLogic Server | CWE-502 | — | |
| #VU18244 | Lenin ZapataRelated Posts | Improper access control in Related Posts | CWE-284 | — | |
| CVE-2019-25141 | wpecommerce, alexanderfoxcEasy WP SMTP | Deserialization of Untrusted Data in Easy WP SMTP | CWE-502 | — | |
| CVE-2019-7816 | AdobeColdFusion | Dangerous file upload in ColdFusion | CWE-434 | — | |
| #VU17879 | GoogleGoogle Chrome | Exposed dangerous method or function in Google Chromium | — | — | |
| CVE-2018-18956 | GNUSuricata | Segmentation fault in Suricata | CWE-20 | — | |
| CVE-2018-15454 | Cisco Systems, IncCisco ASA 5500-X Series | Input validation error in Cisco Systems, Inc products | CWE-20 | — | |
| #VU15547 | MicrosoftMicrosoft Word | Logic error in Microsoft Office and Microsoft Word | CWE-20 | — | |
| CVE-2018-9206 | blueimpjQuery File Upload | Arbitrary file upload in jQuery File Upload | CWE-434 | — | |
| CVE-2018-19207 | WordPress.ORGWP GDPR Compliance | Privilege escalation in WP GDPR Compliance | CWE-264 | — |
Showing 61–80 of 312 results