Complete index
Zero-Day Vulnerability Archive
Search all tracked zero-day vulnerabilities and narrow the results by year, vendor, software, weakness type, or presence in the CISA and ENISA known exploited vulnerability catalogs.
| CVE | Vendor / Product | Vulnerability | CWE | Discovered | KEV |
|---|---|---|---|---|---|
| CVE-2023-32434 | Apple Inc.Apple iOS | Integer overflow in Apple iOS and iPadOS | CWE-190 | CISA KEVENISA KEV | |
| CVE-2023-21237 | GooglePixel | Information exposure in Pixel | CWE-200 | CISA KEVENISA KEV | |
| CVE-2023-20867 | BroadcomVMware Tools | Improper Authentication in VMware Tools | CWE-287 | CISA KEVENISA KEV | |
| CVE-2023-27997 | Fortinet, IncFortiOS | Heap-based buffer overflow in Fortinet, Inc products | CWE-122 | CISA KEVENISA KEV | |
| CVE-2023-38198 | Neilpang (neil)acme.sh | OS Command Injection in acme.sh | CWE-78 | — | |
| CVE-2023-3079 | GoogleGoogle Chrome | Type Confusion in Google Chromium | CWE-843 | CISA KEVENISA KEV | |
| CVE-2023-34362 | UnknownMOVEit Transfer | SQL injection in MOVEit Transfer | CWE-89 | CISA KEVENISA KEV | |
| #VU76737 | GIGABYTE GlobalUEFI firmware | Embedded malicious code (backdoor) in GIGABYTE Global products | CWE-506 | — | |
| #VU76599 | MediaBrowserEmby Server | Missing Authorization in Emby Server | CWE-862 | — | |
| CVE-2023-2868 | Barracuda NetworksEmail Security Gateway (ESG) | OS Command Injection in Email Security Gateway (ESG) | CWE-78 | CISA KEVENISA KEV | |
| CVE-2023-32373 | Apple Inc.Apple iOS | Use-after-free in WebKitGTK+ and WPE WebKit | CWE-416 | CISA KEVENISA KEV | |
| CVE-2023-28204 | Apple Inc.Apple iOS | Out-of-bounds read in WebKitGTK+ and WPE WebKit | CWE-125 | CISA KEVENISA KEV | |
| CVE-2023-32409 | Apple Inc.Apple iOS | Buffer overflow in WebKitGTK+ and WPE WebKit | CWE-119 | CISA KEVENISA KEV | |
| CVE-2023-24932 | MicrosoftMicrosoft Windows | Security features bypass in Microsoft Windows and Windows Server | CWE-254 | — | |
| CVE-2023-29336 | MicrosoftMicrosoft Windows | Use-after-free in Microsoft Windows and Windows Server | CWE-416 | CISA KEVENISA KEV | |
| CVE-2023-21492 | SamsungSamsung Mobile Firmware | Inclusion of sensitive information in log files in Samsung Mobile Firmware | CWE-532 | CISA KEVENISA KEV | |
| CVE-2023-2136 | GoogleGoogle Chrome | Integer overflow in Google Chromium | CWE-190 | CISA KEVENISA KEV | |
| CVE-2023-2033 | GoogleGoogle Chrome | Type Confusion in Google Chromium | CWE-843 | CISA KEVENISA KEV | |
| CVE-2023-28252 | MicrosoftMicrosoft Windows | Buffer overflow in Microsoft Windows and Windows Server | CWE-119 | CISA KEVENISA KEV | |
| CVE-2023-28205 | Apple Inc.Apple iOS | Use-after-free in WebKitGTK+ and WPE WebKit | CWE-416 | CISA KEVENISA KEV |
Showing 61–80 of 98 results