Complete index
Zero-Day Vulnerability Archive
Search all tracked zero-day vulnerabilities and narrow the results by year, vendor, software, weakness type, or presence in the CISA and ENISA known exploited vulnerability catalogs.
| CVE | Vendor / Product | Vulnerability | CWE | Discovered | KEV |
|---|---|---|---|---|---|
| CVE-2025-31200 | Apple Inc.Apple iOS | Buffer overflow in Apple iOS and iPadOS | CWE-119 | CISA KEVENISA KEV | |
| CVE-2025-29824 | MicrosoftMicrosoft Windows | Use-after-free in Microsoft Windows and Windows Server | CWE-416 | CISA KEVENISA KEV | |
| CVE-2025-3928 | CommvaultCommvault | Input validation error in Commvault | CWE-20 | CISA KEVENISA KEV | |
| CVE-2025-22457 | IvantiIvanti Connect Secure (formerly Pulse Connect Secure) | Stack-based buffer overflow in Ivanti Connect Secure (formerly Pulse Connect Secure) | CWE-121 | CISA KEVENISA KEV | |
| CVE-2025-21042 | SamsungSamsung Mobile Firmware | Out-of-bounds write in Samsung Mobile Firmware | CWE-787 | CISA KEVENISA KEV | |
| CVE-2025-27915 | Synacor Inc.Zimbra Collaboration | Stored cross-site scripting in Zimbra Collaboration | CWE-79 | CISA KEVENISA KEV | |
| CVE-2025-30355 | Matrix.orgSynapse | Input validation error in Synapse | CWE-20 | — | |
| CVE-2025-2783 | GoogleGoogle Chrome | Input validation error in Google Chromium | CWE-20 | CISA KEVENISA KEV | |
| CVE-2025-9491 | MicrosoftMicrosoft Windows | Spoofing attack in Microsoft Windows and Windows Server | CWE-451 | — | |
| CVE-2025-30406 | GladinetCentreStack | Use of hard-coded cryptographic key in CentreStack | CWE-321 | CISA KEVENISA KEV | |
| CVE-2025-30066 | tj-actionschanged-files | Embedded malicious code (backdoor) in changed-files | CWE-506 | CISA KEVENISA KEV | |
| CVE-2025-21590 | Juniper Networks, Inc.Junos OS | Permissions, Privileges, and Access Controls in Junos OS | CWE-264 | CISA KEVENISA KEV | |
| CVE-2025-30154 | reviewdogreviewdog | Embedded malicious code (backdoor) in reviewdog | CWE-506 | CISA KEVENISA KEV | |
| CVE-2025-24201 | Apple Inc.Apple iOS | Out-of-bounds write in WebKitGTK+ and WPE WebKit | CWE-787 | CISA KEVENISA KEV | |
| CVE-2025-26633 | MicrosoftMicrosoft Windows | Input validation error in Microsoft Windows and Windows Server | CWE-20 | CISA KEVENISA KEV | |
| CVE-2025-24983 | MicrosoftMicrosoft Windows | Use-after-free in Microsoft Windows and Windows Server | CWE-416 | CISA KEVENISA KEV | |
| CVE-2025-24984 | MicrosoftMicrosoft Windows | Inclusion of Sensitive Information in Log Files in Microsoft Windows and Windows Server | CWE-532 | CISA KEVENISA KEV | |
| CVE-2025-24993 | MicrosoftMicrosoft Windows | Heap-based buffer overflow in Microsoft Windows and Windows Server | CWE-122 | CISA KEVENISA KEV | |
| CVE-2025-24991 | MicrosoftMicrosoft Windows | Out-of-bounds read in Microsoft Windows and Windows Server | CWE-125 | CISA KEVENISA KEV | |
| CVE-2025-24985 | MicrosoftMicrosoft Windows | Integer overflow in Microsoft Windows and Windows Server | CWE-190 | CISA KEVENISA KEV |
Showing 61–80 of 105 results