Complete index
Zero-Day Vulnerability Archive
Search all tracked zero-day vulnerabilities and narrow the results by year, vendor, software, weakness type, or presence in the CISA and ENISA known exploited vulnerability catalogs.
| CVE | Vendor / Product | Vulnerability | CWE | Discovered | KEV |
|---|---|---|---|---|---|
| CVE-2021-30657 | Apple Inc.macOS | Security features bypass in macOS | CWE-254 | CISA KEVENISA KEV | |
| CVE-2021-20023 | SonicWallSonicWall On-premise Email Security (ES) | Path traversal in SonicWall On-premise Email Security (ES) and SonicWall Hosted Email Security (HES) | CWE-22 | CISA KEVENISA KEV | |
| CVE-2021-21224 | GoogleGoogle Chrome | Type Confusion in Google Chrome | CWE-843 | CISA KEVENISA KEV | |
| CVE-2021-22893 | Pulse Secure moved to IvantiIvanti Connect Secure (formerly Pulse Connect Secure) | Improper Authentication in Ivanti Connect Secure (formerly Pulse Connect Secure) | CWE-287 | CISA KEVENISA KEV | |
| CVE-2021-28310 | MicrosoftMicrosoft Windows | Buffer overflow in Microsoft Windows and Windows Server | CWE-119 | CISA KEVENISA KEV | |
| CVE-2021-20022 | SonicWallSonicWall On-premise Email Security (ES) | Arbitrary file upload in SonicWall On-premise Email Security (ES) and SonicWall Hosted Email Security (HES) | CWE-434 | CISA KEVENISA KEV | |
| CVE-2021-20021 | SonicWallSonicWall On-premise Email Security (ES) | Improper Authentication in SonicWall On-premise Email Security (ES) and SonicWall Hosted Email Security (HES) | CWE-287 | CISA KEVENISA KEV | |
| CVE-2021-1879 | Apple Inc.Apple iOS | Universal cross-site scripting in WebKitGTK+ and WPE WebKit | CWE-79 | CISA KEVENISA KEV | |
| CVE-2021-21193 | GoogleGoogle Chrome | Use-after-free in Google Chrome | CWE-416 | CISA KEVENISA KEV | |
| CVE-2021-24175 | Posimyth ThemesThe Plus Addons for Elementor Page Builder | Improper Authentication in The Plus Addons for Elementor Page Builder | CWE-287 | — | |
| CVE-2021-25370 | SamsungSamsung Mobile Firmware | Use-after-free in Samsung Mobile Firmware | CWE-416 | CISA KEVENISA KEV | |
| CVE-2021-25369 | SamsungSamsung Mobile Firmware | Improper access control in Samsung Mobile Firmware | CWE-284 | CISA KEVENISA KEV | |
| CVE-2021-25337 | SamsungSamsung Mobile Firmware | Permissions, Privileges, and Access Controls in Samsung Mobile Firmware | CWE-264 | CISA KEVENISA KEV | |
| #VU51219 | Super Micro Computer, Inc.X10SL7-F, X10SLA-F, X10SLH-F, X10SLL-F, X10SLL-S/-SF, X10SLL+-F, X10SLM-F, X10SLM+-F, X10SLM+-LN4F | Security restrictions bypass in Super Micro Computer, Inc. products | CWE-264 | — | |
| CVE-2021-26855 | MicrosoftMicrosoft Exchange Server | Server-Side Request Forgery (SSRF) in Microsoft Exchange Server | CWE-918 | CISA KEVENISA KEV | |
| CVE-2021-26857 | MicrosoftMicrosoft Exchange Server | Input validation error in Microsoft Exchange Server | CWE-20 | CISA KEVENISA KEV | |
| CVE-2021-26858 | MicrosoftMicrosoft Exchange Server | Input validation error in Microsoft Exchange Server | CWE-20 | CISA KEVENISA KEV | |
| CVE-2021-27065 | MicrosoftMicrosoft Exchange Server | Input validation error in Microsoft Exchange Server | CWE-20 | CISA KEVENISA KEV | |
| CVE-2021-21166 | GoogleGoogle Chrome | Improper control of a resource through its lifetime in Google Chrome | — | CISA KEVENISA KEV | |
| CVE-2021-21017 | AdobeAdobe Reader | Heap-based buffer overflow in Adobe Reader and Adobe Acrobat | CWE-122 | CISA KEVENISA KEV |
Showing 61–80 of 89 results