Complete index
Zero-Day Vulnerability Archive
Search all tracked zero-day vulnerabilities and narrow the results by year, vendor, software, weakness type, or presence in the CISA and ENISA known exploited vulnerability catalogs.
| CVE | Vendor / Product | Vulnerability | CWE | Discovered | KEV |
|---|---|---|---|---|---|
| CVE-2026-6973 | IvantiEndpoint Manager Mobile (formerly MobileIron Core) | Input validation error in Endpoint Manager Mobile (formerly MobileIron Core) | CWE-20 | CISA KEVENISA KEV | |
| CVE-2026-1340 | IvantiEndpoint Manager Mobile (formerly MobileIron Core) | Code Injection in Endpoint Manager Mobile (formerly MobileIron Core) | CWE-94 | CISA KEVENISA KEV | |
| CVE-2026-1281 | IvantiEndpoint Manager Mobile (formerly MobileIron Core) | Code Injection in Endpoint Manager Mobile (formerly MobileIron Core) | CWE-94 | CISA KEV | |
| CVE-2025-4428 | IvantiEndpoint Manager Mobile (formerly MobileIron Core) | Code Injection in Endpoint Manager Mobile (formerly MobileIron Core) | CWE-94 | CISA KEVENISA KEV | |
| CVE-2025-4427 | IvantiEndpoint Manager Mobile (formerly MobileIron Core) | Authentication bypass using an alternate path or channel in Endpoint Manager Mobile (formerly MobileIron Core) | CWE-288 | CISA KEVENISA KEV | |
| CVE-2025-22457 | IvantiIvanti Connect Secure (formerly Pulse Connect Secure) | Stack-based buffer overflow in Ivanti Connect Secure (formerly Pulse Connect Secure) | CWE-121 | CISA KEVENISA KEV | |
| CVE-2025-0282 | IvantiIvanti Connect Secure (formerly Pulse Connect Secure) | Stack-based buffer overflow in Ivanti Connect Secure (formerly Pulse Connect Secure) | CWE-121 | CISA KEVENISA KEV | |
| CVE-2024-9381 | IvantiIvanti Cloud Services Appliance (CSA) | Path traversal in Ivanti Cloud Services Appliance (CSA) | CWE-22 | — | |
| CVE-2024-9380 | IvantiIvanti Cloud Services Appliance (CSA) | OS Command Injection in Ivanti Cloud Services Appliance (CSA) | CWE-78 | CISA KEVENISA KEV | |
| CVE-2024-9379 | IvantiIvanti Cloud Services Appliance (CSA) | SQL injection in Ivanti Cloud Services Appliance (CSA) | CWE-89 | CISA KEVENISA KEV | |
| CVE-2024-8963 | IvantiIvanti Cloud Services Appliance (CSA) | Path traversal in Ivanti Cloud Services Appliance (CSA) | CWE-22 | CISA KEVENISA KEV | |
| CVE-2023-38035 | IvantiMobileIron Sentry | Improper Authentication in MobileIron Sentry | CWE-287 | CISA KEVENISA KEV | |
| CVE-2023-35081 | IvantiEndpoint Manager Mobile (formerly MobileIron Core) | Path traversal in Endpoint Manager Mobile (formerly MobileIron Core) | CWE-22 | CISA KEVENISA KEV | |
| CVE-2023-35078 | IvantiEndpoint Manager Mobile (formerly MobileIron Core) | Improper Authentication in Endpoint Manager Mobile (formerly MobileIron Core) | CWE-287 | CISA KEVENISA KEV | |
| CVE-2021-44529 | IvantiEndpoint Manager | Embedded malicious code (backdoor) in Endpoint Manager | CWE-506 | CISA KEVENISA KEV |
Showing 1–15 of 15 results