Complete index
Zero-Day Vulnerability Archive
Search all tracked zero-day vulnerabilities and narrow the results by year, vendor, software, weakness type, or presence in the CISA and ENISA known exploited vulnerability catalogs.
| CVE | Vendor / Product | Vulnerability | CWE | Discovered | KEV |
|---|---|---|---|---|---|
| CVE-2026-85880 | MicrosoftMicrosoft Windows | Heap-based buffer overflow in Microsoft Windows and Windows Server | CWE-122 | CISA KEV | |
| CVE-2026-81963 | MicrosoftMicrosoft Windows | Insecure link following in Microsoft Windows and Windows Server | CWE-59 | CISA KEV | |
| CVE-2026-68820 | MicrosoftMicrosoft Windows | Use-after-free in Microsoft Windows and Windows Server | CWE-416 | CISA KEV | |
| CVE-2026-56164 | MicrosoftMicrosoft SharePoint Server | Missing Authentication for Critical Function in Microsoft SharePoint Server | CWE-306 | CISA KEVENISA KEV | |
| CVE-2026-56155 | MicrosoftMicrosoft Windows | Insufficient granularity of access control in Microsoft Windows and Windows Server | CWE-1220 | CISA KEVENISA KEV | |
| CVE-2026-45498 | MicrosoftWindows Defender | Input validation error in Windows Defender | CWE-20 | CISA KEVENISA KEV | |
| CVE-2026-41091 | MicrosoftMicrosoft Malware Protection Engine | Link following in Microsoft Malware Protection Engine | CWE-59 | CISA KEVENISA KEV | |
| CVE-2026-42897 | MicrosoftMicrosoft Exchange Server | Stored cross-site scripting in Microsoft Exchange Server | CWE-79 | CISA KEVENISA KEV | |
| CVE-2026-33825 | MicrosoftWindows Defender | Insufficient Granularity of Access Control in Windows Defender | CWE-1220 | CISA KEVENISA KEV | |
| CVE-2026-32201 | MicrosoftMicrosoft SharePoint Server | Input validation error in Microsoft SharePoint Server | CWE-20 | CISA KEVENISA KEV | |
| CVE-2026-21519 | MicrosoftMicrosoft Windows | Type Confusion in Microsoft Windows and Windows Server | CWE-843 | CISA KEVENISA KEV | |
| CVE-2026-21525 | MicrosoftWindows Server | NULL pointer dereference in Microsoft Windows and Windows Server | CWE-476 | CISA KEVENISA KEV | |
| CVE-2026-21533 | MicrosoftWindows Server | Improper privilege management in Microsoft Windows and Windows Server | CWE-269 | CISA KEVENISA KEV | |
| CVE-2026-21513 | MicrosoftMicrosoft Windows | Protection Mechanism Failure in Microsoft products | CWE-693 | CISA KEVENISA KEV | |
| CVE-2026-21510 | MicrosoftMicrosoft Windows | Protection Mechanism Failure in Microsoft Windows and Windows Server | CWE-693 | CISA KEVENISA KEV | |
| CVE-2026-21514 | MicrosoftMicrosoft Office | Reliance on Untrusted Inputs in a Security Decision in Microsoft products | CWE-807 | CISA KEVENISA KEV | |
| CVE-2026-21509 | MicrosoftMicrosoft Office | Reliance on Untrusted Inputs in a Security Decision in Microsoft Office | CWE-807 | CISA KEVENISA KEV | |
| CVE-2026-20805 | MicrosoftMicrosoft Windows | Information disclosure in Microsoft Windows and Windows Server | CWE-200 | CISA KEVENISA KEV | |
| CVE-2025-62221 | MicrosoftMicrosoft Windows | Use-after-free in Microsoft Windows and Windows Server | CWE-416 | CISA KEVENISA KEV | |
| CVE-2025-62215 | MicrosoftMicrosoft Windows | Race condition in Microsoft Windows and Windows Server | CWE-362 | CISA KEVENISA KEV |
Showing 1–20 of 337 results