Complete index
Zero-Day Vulnerability Archive
Search all tracked zero-day vulnerabilities and narrow the results by year, vendor, software, weakness type, or presence in the CISA and ENISA known exploited vulnerability catalogs.
| CVE | Vendor / Product | Vulnerability | CWE | Discovered | KEV |
|---|---|---|---|---|---|
| CVE-2025-22226 | BroadcomVMware ESXi | Out-of-bounds read in VMware ESXi | CWE-125 | CISA KEVENISA KEV | |
| CVE-2025-22225 | BroadcomVMware ESXi | Permissions, Privileges, and Access Controls in VMware ESXi | CWE-264 | CISA KEVENISA KEV | |
| CVE-2025-22224 | BroadcomVMware ESXi | Heap-based buffer overflow in VMware ESXi | CWE-122 | CISA KEVENISA KEV | |
| CVE-2024-53197 | GoogleGoogle Android | Out-of-bounds write in Linux kernel | CWE-787 | CISA KEVENISA KEV | |
| CVE-2024-50302 | GoogleGoogle Android | Memory leak in Linux kernel | CWE-401 | CISA KEVENISA KEV | |
| CVE-2025-0289 | Paragon Technologie GmbHPartition Manager | Improper access control in BioNTdrv.sys and Partition Manager | CWE-284 | — | |
| CVE-2024-58136 | Yii SoftwareYii | Improper protection of alternate path in Yii | CWE-424 | CISA KEVENISA KEV | |
| CVE-2025-32432 | Pixel & Tonic, Inc.Craft CMS | Code Injection in Craft CMS | CWE-94 | CISA KEVENISA KEV | |
| CVE-2025-1094 | PostgreSQL Global Development GroupPostgreSQL | Input validation error in PostgreSQL | CWE-20 | — | |
| CVE-2025-21418 | MicrosoftMicrosoft Windows | Heap-based buffer overflow in Microsoft Windows and Windows Server | CWE-122 | CISA KEVENISA KEV | |
| CVE-2025-21391 | MicrosoftMicrosoft Windows | Link following in Microsoft Windows and Windows Server | CWE-59 | CISA KEVENISA KEV | |
| CVE-2025-43200 | Apple Inc.Apple iOS | Input validation error in iPadOS and Apple iOS | CWE-20 | CISA KEVENISA KEV | |
| CVE-2025-24200 | Apple Inc.Apple iOS | Security features bypass in Apple iOS and iPadOS | CWE-254 | CISA KEVENISA KEV | |
| CVE-2025-25181 | AdvantiveVeraCore | SQL injection in VeraCore | CWE-89 | CISA KEVENISA KEV | |
| CVE-2024-53104 | GoogleGoogle Android | Out-of-bounds write in Linux kernel | CWE-787 | CISA KEVENISA KEV | |
| CVE-2025-0626 | ContecCMS8000 Patient Monitor | Hidden functionality in CMS8000 Patient Monitor | CWE-912 | — | |
| CVE-2025-0994 | TrimbleCityworks | Deserialization of Untrusted Data in Cityworks and Cityworks with office companion | CWE-502 | CISA KEVENISA KEV | |
| CVE-2024-40891 | ZyXEL Communications Corp.Zyxel CPE Series | Command Injection in Zyxel CPE Series | CWE-77 | CISA KEVENISA KEV | |
| CVE-2025-24085 | Apple Inc.Apple iOS | Use-after-free in Apple iOS and iPadOS | CWE-416 | CISA KEVENISA KEV | |
| CVE-2025-23006 | SonicWallSonicWall SMA 1000 | Deserialization of untrusted data in SonicWall SMA 1000 | CWE-502 | CISA KEVENISA KEV |
Showing 81–100 of 105 results