Complete index
Zero-Day Vulnerability Archive
Search all tracked zero-day vulnerabilities and narrow the results by year, vendor, software, weakness type, or presence in the CISA and ENISA known exploited vulnerability catalogs.
| CVE | Vendor / Product | Vulnerability | CWE | Discovered | KEV |
|---|---|---|---|---|---|
| CVE-2025-41244 | BroadcomVMware Tools | Improper access control in VMware Tools | CWE-284 | CISA KEVENISA KEV | |
| CVE-2025-11371 | GladinetCentreStack | Path traversal in CentreStack | CWE-22 | CISA KEVENISA KEV | |
| CVE-2025-20362 | Cisco Systems, IncCisco Secure Firewall Adaptive Security Appliance (ASA) | Missing authorization in Cisco Adaptive Security Appliance (ASA) and Cisco Firewall Threat Defense (FTD) | CWE-862 | CISA KEVENISA KEV | |
| CVE-2025-20352 | Cisco Systems, IncCisco IOS XE | Stack-based buffer overflow in Cisco IOS XE | CWE-121 | CISA KEVENISA KEV | |
| CVE-2025-59689 | LibraesvaEmail Security Gateway | OS command injection in Email Security Gateway | CWE-78 | CISA KEVENISA KEV | |
| CVE-2025-10585 | GoogleGoogle Chrome | Type Confusion in Google Chromium | CWE-843 | CISA KEVENISA KEV | |
| CVE-2025-21043 | Unknown | Out-of-bounds write in Samsung Mobile Firmware | CWE-787 | CISA KEVENISA KEV | |
| CVE-2025-53690 | SitecoreSitecore Experience Platform | Deserialization of Untrusted Data in Sitecore products | CWE-502 | CISA KEVENISA KEV | |
| CVE-2025-48543 | GoogleGoogle Android | Improper input validation in Google Android | CWE-20 | CISA KEVENISA KEV | |
| CVE-2025-38352 | GoogleGoogle Android | Race condition in Linux kernel | CWE-362 | CISA KEVENISA KEV | |
| CVE-2025-55177 | WhatsAppWhatsApp for Mac | Improper authorization in WhatsApp products | CWE-285 | CISA KEVENISA KEV | |
| CVE-2025-57819 | FreePBXFreePBX | SQL injection in FreePBX | CWE-89 | CISA KEVENISA KEV | |
| CVE-2025-7775 | CitrixCitrix Netscaler ADC, Citrix NetScaler Gateway | Buffer overflow in Citrix Netscaler ADC and Citrix NetScaler Gateway | CWE-119 | CISA KEVENISA KEV | |
| CVE-2025-43300 | Apple Inc.Apple iOS | Out-of-bounds write in Apple iOS and iPadOS | CWE-787 | CISA KEVENISA KEV | |
| CVE-2025-25256 | Fortinet, IncFortiSIEM | OS Command Injection in FortiSIEM | CWE-78 | — | |
| CVE-2025-54948 | Trend MicroApex One | OS Command Injection in Apex One | CWE-78 | CISA KEVENISA KEV | |
| CVE-2025-8088 | RARLABWinRAR | Path traversal in WinRAR | CWE-22 | CISA KEVENISA KEV | |
| CVE-2025-53770 | MicrosoftMicrosoft SharePoint Server | Deserialization of Untrusted Data in Microsoft SharePoint Server | CWE-502 | CISA KEVENISA KEV | |
| CVE-2025-54313 | Prettiereslint-config-prettier | Embedded malicious code (backdoor) in eslint-config-prettier | CWE-506 | CISA KEV | |
| CVE-2025-6558 | GoogleGoogle Chrome | Input validation error in Google Chromium | CWE-20 | CISA KEVENISA KEV |
Showing 21–40 of 105 results