Complete index
Zero-Day Vulnerability Archive
Search all tracked zero-day vulnerabilities and narrow the results by year, vendor, software, weakness type, or presence in the CISA and ENISA known exploited vulnerability catalogs.
| CVE | Vendor / Product | Vulnerability | CWE | Discovered | KEV |
|---|---|---|---|---|---|
| CVE-2021-45461 | FreePBXPhone Apps | Input validation error in Phone Apps | CWE-20 | — | |
| CVE-2021-4102 | GoogleGoogle Chrome | Use-after-free in Google Chromium | CWE-416 | CISA KEVENISA KEV | |
| CVE-2021-44529 | IvantiEndpoint Manager | Embedded malicious code (backdoor) in Endpoint Manager | CWE-506 | CISA KEVENISA KEV | |
| CVE-2021-43890 | MicrosoftMicrosoft Windows | Permissions, Privileges, and Access Controls in Microsoft Windows and Windows Server | CWE-264 | CISA KEVENISA KEV | |
| #VU58226 | FatPipe Networks Inc.IPVPN, MPVPN, WARP | Arbitrary file upload in FatPipe Networks Inc. products | CWE-434 | — | |
| CVE-2021-42292 | MicrosoftMicrosoft Office | Input validation error in Microsoft Office and Microsoft Excel | CWE-20 | CISA KEVENISA KEV | |
| CVE-2021-42321 | MicrosoftMicrosoft Exchange Server | Input validation error in Microsoft Exchange Server | CWE-20 | CISA KEVENISA KEV | |
| CVE-2021-1048 | GoogleGoogle Android | Use-after-free in Google Android | CWE-416 | CISA KEVENISA KEV | |
| CVE-2021-38003 | GoogleGoogle Chrome | Improperly implemented security check for standard in Google Chromium | CWE-358 | CISA KEVENISA KEV | |
| CVE-2021-38000 | GoogleGoogle Chrome | Exposed dangerous method or function in Google Chromium | CWE-749 | CISA KEVENISA KEV | |
| CVE-2021-42258 | BQE SoftwareBillQuick Web Suite | SQL injection in BillQuick Web Suite | CWE-89 | CISA KEVENISA KEV | |
| CVE-2021-40449 | MicrosoftMicrosoft Windows | Use-after-free in Microsoft Windows and Windows Server | CWE-416 | CISA KEVENISA KEV | |
| CVE-2021-30883 | Apple Inc.Apple iOS | Integer overflow in iPadOS and Apple iOS | CWE-190 | CISA KEVENISA KEV | |
| CVE-2021-41773 | Apache FoundationApache HTTP Server | Path traversal in Apache HTTP Server | CWE-22 | CISA KEVENISA KEV | |
| CVE-2021-37976 | GoogleGoogle Chrome | Information disclosure in Google Chromium | CWE-200 | CISA KEVENISA KEV | |
| CVE-2021-37975 | GoogleGoogle Chrome | Use-after-free in Google Chromium | CWE-416 | CISA KEVENISA KEV | |
| CVE-2021-37973 | GoogleGoogle Chrome | Use-after-free in Google Chrome | CWE-416 | CISA KEVENISA KEV | |
| CVE-2021-30869 | Apple Inc.macOS | Type Confusion in macOS | CWE-843 | CISA KEVENISA KEV | |
| CVE-2021-31010 | Apple Inc.macOS | Deserialization of Untrusted Data in macOS | CWE-502 | CISA KEVENISA KEV | |
| #VU57645 | EntroLinkPPX-AnyLink 6004, PPX-AnyLink 6006, PPX-AnyLink 6900, PPX-AnyLink 6900F, PPX-AnyLink 6904, PPX-AnyLink 8000 | Code Injection in EntroLink products | CWE-94 | — |
Showing 1–20 of 89 results