Complete index
Zero-Day Vulnerability Archive
Search all tracked zero-day vulnerabilities and narrow the results by year, vendor, software, weakness type, or presence in the CISA and ENISA known exploited vulnerability catalogs.
| CVE | Vendor / Product | Vulnerability | CWE | Discovered | KEV |
|---|---|---|---|---|---|
| CVE-2024-1709 | ConnectWiseScreenConnect | Authentication bypass using an alternate path or channel in ScreenConnect | CWE-288 | CISA KEVENISA KEV | |
| CVE-2024-21410 | MicrosoftMicrosoft Exchange Server | Exposure of Resource to Wrong Sphere in Microsoft Exchange Server | CWE-668 | CISA KEVENISA KEV | |
| CVE-2023-50358 | QNAP Systems, Inc.QNAP QTS | OS Command Injection in QuTS hero and QNAP QTS | CWE-78 | — | |
| CVE-2024-21412 | MicrosoftMicrosoft Windows | Security features bypass in Microsoft Windows and Windows Server | CWE-254 | CISA KEVENISA KEV | |
| CVE-2024-21351 | MicrosoftMicrosoft Windows | Security features bypass in Microsoft Windows and Windows Server | CWE-254 | CISA KEVENISA KEV | |
| CVE-2024-21762 | Fortinet, IncFortiOS | Out-of-bounds write in FortiOS | CWE-787 | CISA KEVENISA KEV | |
| CVE-2024-21893 | Pulse Secure moved to IvantiIvanti Connect Secure (formerly Pulse Connect Secure) | Server-Side Request Forgery (SSRF) in Ivanti Policy Secure (formerly Pulse Policy Secure) and Ivanti Connect Secure (formerly Pulse Connect Secure) | CWE-918 | CISA KEVENISA KEV | |
| CVE-2024-23842 | Hitron SystemsDVR LGUVR-16H | Use of default credentials in DVR LGUVR-16H | CWE-1392 | — | |
| CVE-2024-22772 | Hitron SystemsDVR LGUVR-8H | Use of default credentials in DVR LGUVR-8H | CWE-1392 | — | |
| CVE-2024-22771 | Hitron SystemsDVR LGUVR-4H | Use of default credentials in DVR LGUVR-4H | CWE-1392 | — | |
| CVE-2024-22770 | Hitron SystemsDVR HVR-16781 | Use of default credentials in DVR HVR-16781 | CWE-1392 | — | |
| CVE-2024-22769 | Hitron SystemsDVR HVR-8781 | Use of default credentials in DVR HVR-8781 | CWE-1392 | — | |
| CVE-2024-22768 | Hitron SystemsDVR HVR-4781 | Use of default credentials in DVR HVR-4781 | CWE-1392 | — | |
| CVE-2024-23222 | Apple Inc.Apple iOS | Type confusion in WebKitGTK+ and WPE WebKit | CWE-843 | CISA KEVENISA KEV | |
| CVE-2023-6549 | CitrixCitrix NetScaler Gateway | Buffer overflow in Citrix Netscaler ADC and Citrix NetScaler Gateway | CWE-119 | CISA KEVENISA KEV | |
| CVE-2023-6548 | CitrixCitrix NetScaler Gateway | Code Injection in Citrix Netscaler ADC and Citrix NetScaler Gateway | CWE-94 | CISA KEVENISA KEV | |
| CVE-2024-0519 | GoogleGoogle Chrome | Buffer overflow in Google Chromium | CWE-119 | CISA KEVENISA KEV | |
| CVE-2024-21887 | Pulse Secure moved to IvantiIvanti Connect Secure (formerly Pulse Connect Secure) | OS Command Injection in Ivanti Policy Secure (formerly Pulse Policy Secure) and Ivanti Connect Secure (formerly Pulse Connect Secure) | CWE-78 | CISA KEVENISA KEV | |
| CVE-2023-46805 | Pulse Secure moved to IvantiIvanti Connect Secure (formerly Pulse Connect Secure) | Improper Authentication in Ivanti Policy Secure (formerly Pulse Policy Secure) and Ivanti Connect Secure (formerly Pulse Connect Secure) | CWE-287 | CISA KEVENISA KEV |
Showing 81–99 of 99 results