Complete index
Zero-Day Vulnerability Archive
Search all tracked zero-day vulnerabilities and narrow the results by year, vendor, software, weakness type, or presence in the CISA and ENISA known exploited vulnerability catalogs.
| CVE | Vendor / Product | Vulnerability | CWE | Discovered | KEV |
|---|---|---|---|---|---|
| CVE-2025-14733 | WatchGuardFireware OS | Out-of-bounds write in Fireware OS | CWE-787 | CISA KEVENISA KEV | |
| CVE-2025-20393 | Cisco Systems, IncSecure Email Gateway | Input validation error in Cisco Secure Email and Web Manager and Secure Email Gateway | CWE-20 | CISA KEVENISA KEV | |
| CVE-2025-40602 | SonicWallSonicWall SMA 1000 | Missing authorization in SonicWall SMA 1000 | CWE-862 | CISA KEVENISA KEV | |
| CVE-2025-43529 | Apple Inc.Apple iOS | Use-after-free in WebKitGTK+ and WPE WebKit | CWE-416 | CISA KEVENISA KEV | |
| CVE-2025-8110 | gogs.iogogs | Path traversal in gogs | CWE-22 | CISA KEVENISA KEV | |
| CVE-2025-14174 | GoogleGoogle Chrome | Out-of-bounds write in Google Chromium | CWE-787 | CISA KEVENISA KEV | |
| CVE-2025-15556 | Notepad++Notepad++ | Improper verification of cryptographic signature in Notepad++ | CWE-347 | — | |
| CVE-2025-62221 | MicrosoftMicrosoft Windows | Use-after-free in Microsoft Windows and Windows Server | CWE-416 | CISA KEVENISA KEV | |
| CVE-2025-48633 | GoogleGoogle Android | Exposure of sensitive information to an unauthorized actor in Google Android | CWE-200 | CISA KEVENISA KEV | |
| CVE-2025-48572 | GoogleGoogle Android | Improper input validation in Google Android | CWE-20 | CISA KEVENISA KEV | |
| CVE-2025-14611 | GladinetCentreStack | Use of hard-coded cryptographic key in Triofox and CentreStack | CWE-321 | CISA KEVENISA KEV | |
| CVE-2025-58034 | Fortinet, IncFortiWeb | OS Command Injection in FortiWeb | CWE-78 | CISA KEVENISA KEV | |
| CVE-2025-13223 | GoogleGoogle Chrome | Type confusion in Google Chromium | CWE-843 | CISA KEVENISA KEV | |
| CVE-2025-64446 | Fortinet, IncFortiWeb | Path traversal in FortiWeb | CWE-22 | CISA KEVENISA KEV | |
| CVE-2025-62215 | MicrosoftMicrosoft Windows | Race condition in Microsoft Windows and Windows Server | CWE-362 | CISA KEVENISA KEV | |
| CVE-2025-61932 | MOTEX Inc.Lanscope Endpoint Manager (On-Premises) | Improper Verification of Source of a Communication Channel in Lanscope Endpoint Manager (On-Premises) | CWE-940 | CISA KEVENISA KEV | |
| CVE-2025-47827 | MicrosoftMicrosoft Windows | Improper verification of cryptographic signature in IGEL OS | CWE-347 | CISA KEVENISA KEV | |
| CVE-2025-59230 | MicrosoftMicrosoft Windows | Improper access control in Microsoft Windows and Windows Server | CWE-284 | CISA KEVENISA KEV | |
| CVE-2025-24990 | MicrosoftMicrosoft Windows | Untrusted pointer dereference in Microsoft Windows and Windows Server | CWE-822 | CISA KEVENISA KEV | |
| CVE-2025-61884 | OracleOracle E-Business Suite | Server-Side Request Forgery (SSRF) in Oracle Configurator and Oracle E-Business Suite | CWE-918 | CISA KEVENISA KEV |
Showing 1–20 of 105 results