Complete index
Zero-Day Vulnerability Archive
Search all tracked zero-day vulnerabilities and narrow the results by year, vendor, software, weakness type, or presence in the CISA and ENISA known exploited vulnerability catalogs.
| CVE | Vendor / Product | Vulnerability | CWE | Discovered | KEV |
|---|---|---|---|---|---|
| #VU27672 | ElementorElementor Pro | Arbitrary file upload in Elementor Pro | CWE-434 | — | |
| CVE-2020-12271 | SophosSophos Firewall | SQL injection in Sophos Firewall | CWE-89 | CISA KEVENISA KEV | |
| #VU27193 | Apple Inc.Apple iOS | Out-of-bounds write in Apple iOS | CWE-787 | — | |
| CVE-2020-1027 | MicrosoftMicrosoft Windows | Buffer overflow in Microsoft Windows and Windows Server | CWE-119 | CISA KEVENISA KEV | |
| CVE-2020-6820 | MozillaMozilla Firefox | Use-after-free in Firefox ESR and Mozilla Firefox | CWE-416 | CISA KEVENISA KEV | |
| CVE-2020-6819 | MozillaMozilla Firefox | Use-after-free in Firefox ESR and Mozilla Firefox | CWE-416 | CISA KEVENISA KEV | |
| CVE-2020-0938 | MicrosoftMicrosoft Windows | Buffer overflow in Microsoft Windows and Windows Server | CWE-119 | CISA KEVENISA KEV | |
| CVE-2020-1020 | MicrosoftMicrosoft Windows | Buffer overflow in Microsoft Windows and Windows Server | CWE-119 | CISA KEVENISA KEV | |
| #VU26285 | Merit LILIN Ent. Co., Ltd.DHD204, DHD204A, DHD208, DHD208A, DHD216, DHD216A, DHD304A, DHD308A, DHD316A, DHD504A, DHD508A, DHD516A | Use of hard-coded credentials in Merit LILIN Ent. Co., Ltd. products | CWE-798 | — | |
| CVE-2020-8468 | Trend MicroApex One | Input validation error in Trend Micro products | CWE-20 | CISA KEVENISA KEV | |
| CVE-2020-8467 | Trend MicroOfficeScan | Code Injection in OfficeScan and Apex One | CWE-94 | CISA KEVENISA KEV | |
| #VU25822 | Unknown | Improper access control in Custom Searchable Data Entry System | CWE-284 | — | |
| #VU25677 | Unknown | Stored cross-site scripting in Async JavaScript | CWE-79 | — | |
| #VU25676 | Unknown | Stored cross-site scripting in 10Web Google Maps - Google Maps builder Plugin | CWE-79 | — | |
| #VU25675 | Unknown | Stored cross-site scripting in Modern Events Calendar Lite | CWE-79 | — | |
| #VU25627 | Unknown | Improper access control in Flexible Checkout Fields for WooCommerce | CWE-284 | — | |
| CVE-2020-6418 | GoogleGoogle Chrome | Type Confusion in Google Chrome | CWE-843 | CISA KEVENISA KEV | |
| CVE-2020-0674 | MicrosoftMicrosoft Internet Explorer | Buffer overflow in Microsoft Internet Explorer | CWE-119 | CISA KEVENISA KEV | |
| CVE-2019-17026 | MozillaMozilla Firefox | Type Confusion in Firefox ESR and Mozilla Firefox | CWE-843 | CISA KEVENISA KEV |
Showing 21–39 of 39 results