Complete index
Zero-Day Vulnerability Archive
Search all tracked zero-day vulnerabilities and narrow the results by year, vendor, software, weakness type, or presence in the CISA and ENISA known exploited vulnerability catalogs.
| CVE | Vendor / Product | Vulnerability | CWE | Discovered | KEV |
|---|---|---|---|---|---|
| CVE-2025-21335 | MicrosoftMicrosoft Windows | Use-after-free in Microsoft Windows and Windows Server | CWE-416 | CISA KEVENISA KEV | |
| CVE-2025-21334 | MicrosoftMicrosoft Windows | Use-after-free in Microsoft Windows and Windows Server | CWE-416 | CISA KEVENISA KEV | |
| CVE-2025-21333 | MicrosoftMicrosoft Windows | Heap-based buffer overflow in Microsoft Windows and Windows Server | CWE-122 | CISA KEVENISA KEV | |
| CVE-2024-55591 | Fortinet, IncFortiOS | Authentication bypass using an alternate path or channel in FortiProxy and FortiOS | CWE-288 | CISA KEVENISA KEV | |
| CVE-2025-0282 | IvantiIvanti Connect Secure (formerly Pulse Connect Secure) | Stack-based buffer overflow in Ivanti Connect Secure (formerly Pulse Connect Secure) | CWE-121 | CISA KEVENISA KEV | |
| CVE-2024-3393 | Palo Alto Networks, Inc.Palo Alto PAN-OS | Improper Check for Unusual or Exceptional Conditions in Palo Alto PAN-OS | CWE-754 | CISA KEVENISA KEV | |
| CVE-2024-12856 | Four-FaithF3x24, F3x36 | OS Command Injection in F3x24 and F3x36 | CWE-78 | — | |
| CVE-2024-12356 | BeyondTrustRemote Support | OS Command Injection in Remote Support and Privileged Remote Access (PRA) | CWE-78 | CISA KEVENISA KEV | |
| CVE-2024-12686 | BeyondTrustRemote Support | OS Command Injection in Remote Support and Privileged Remote Access (PRA) | CWE-78 | CISA KEVENISA KEV | |
| CVE-2024-49138 | MicrosoftMicrosoft Windows | Heap-based buffer overflow in Microsoft Windows and Windows Server | CWE-122 | CISA KEVENISA KEV | |
| CVE-2024-55956 | CleoCleo LexiCom | Arbitrary file upload in Cleo products | CWE-434 | CISA KEVENISA KEV | |
| CVE-2024-47133 | I-O DATAUD-LT1, UD-LT1/EX | OS Command Injection in UD-LT1 and UD-LT1/EX | CWE-78 | — | |
| CVE-2024-45841 | I-O DATAUD-LT1, UD-LT1/EX | Incorrect permission assignment for critical resource in UD-LT1 and UD-LT1/EX | CWE-732 | — | |
| CVE-2024-52564 | I-O DATAUD-LT1, UD-LT1/EX | Inclusion of Undocumented Features or Chicken Bits in UD-LT1 and UD-LT1/EX | CWE-1242 | — | |
| CVE-2024-44309 | Apple Inc.macOS | Universal cross-site scripting in WPE WebKit and WebKitGTK+ | CWE-79 | CISA KEVENISA KEV | |
| CVE-2024-44308 | Apple Inc.macOS | Input validation error in WebKitGTK+ and WPE WebKit | CWE-20 | CISA KEVENISA KEV | |
| CVE-2024-21287 | OracleOracle Agile PLM Framework | Missing Authorization in Oracle Agile PLM Framework | CWE-862 | CISA KEVENISA KEV | |
| CVE-2024-0012 | Palo Alto Networks, Inc.Palo Alto PAN-OS | Improper authentication in Palo Alto PAN-OS | CWE-287 | CISA KEVENISA KEV | |
| CVE-2024-11120 | GeoVisionGV-DSP_LPR_V3, GV-VS11, GV-VS12, GVLX 4 V2, GVLX 4 V3 | OS Command Injection in GeoVision products | CWE-78 | CISA KEVENISA KEV | |
| #VU100575 | Fortinet, IncFortinet FortiClient for Windows | Unprotected storage of credentials in Fortinet FortiClient for Windows | CWE-256 | — |
Showing 181–200 of 1,000 results