
Zero-day Tracker
Zero-Day Tracker is built to help you understand a fully patched system and application cannot guarantee security. All the vulnerabilities listed below are the results of our researches and they have not been disclosed to the vendors or public. Though in the past we have clearly supported responsible disclosure of security vulnerability, now we no longer endorse it.
While we are trying to keep the information as accurate as possible, we cannot guarantee that these vulnerabilities are indeed zero-day since it is a known fact that they may have been circled around among the hackers for a long time.
The list below covers some of the vulnerabilities that we have in our lab and this list will be updated when we see fit.
Date | Product | Versions | Type | Severity | Status | |
|---|---|---|---|---|---|---|
| 2026 | PDF Architect 9 | Current | Local Privlege Escalation | High | Active | |
Vendor:pdfforge Patch:No Platform:Windows Summary:- CVSS Score:- Credits:cobra | ||||||
| 2026 | HP Office Jet Pro 9020 series | Current | Remote Code Execution | Critical | Active | |
Vendor:HP Patch:No Platform:Embedded Device Summary:- CVSS Score:- Credits:0xakm | ||||||
| 2026 | 360 Total Security | Current | Local Privlege Escalation | High | Active | |
Vendor:Qihoo 360 Patch:No Platform:Windows Summary:- CVSS Score:- Credits:jin1337 | ||||||
| 2026 | Avast One | Current | Local Privlege Escalation | High | Active | |
Vendor:Avast Patch:No Platform:Windows Summary:- CVSS Score:- Credits:jin1337 | ||||||
| 2026 | AWS VPN Client | Current | Local Privlege Escalation | High | Active | |
Vendor:AWS Patch:No Platform:Linux Summary:- CVSS Score:- Credits:z22 | qbao | ||||||
| 2026 | Foxit Reader | 2026.* | Remote Code Execution | Critical | Active | |
Vendor:Foxit Patch:No Platform:Windows Summary:- CVSS Score:- Credits:qbao | cobra | ||||||
| 2026 | Typora | Current | Remote Code Execution | Critical | Active | |
Vendor:Typora Patch:No Platform:Windows Summary:- CVSS Score:- Credits:cobra | ||||||
| 2025 | Checkpoint VPN | Current | Local Privlege Escalation | High | Active | |
Vendor:Checkpoint Patch:No Platform:Windows Summary:- CVSS Score:- Credits:cobra | ||||||
| 2025 | Foxit Reader | 2025-2026 | Local Privlege Escalation | High | Active | |
Vendor:Foxit Patch:No Platform:Windows Summary:- CVSS Score:- Credits:cobra | ||||||
| 2024 | Nitro PDF | Current | Remote Code Execution | Critical | Active | |
Vendor:Nitro Patch:Yes Platform:Windows Summary:- CVSS Score:- Credits:cobra | ||||||
| 2024 | Foxit Reader | 2024.* | Remote Code Execution | Critical | Killed | |
Vendor:Foxit Patch:Yes Platform:Windows Summary:- CVSS Score:- Credits:z22 | qbao | ||||||
| 2024 | RocketChat | Current | Remote Code Execution | Critical | Active | |
Vendor:RocketChat Patch:No Platform:Windows Summary:- CVSS Score:- Credits:cobra | ||||||
| 2024 | BitDefender Safepay | Current | Remote Code Execution | Critical | Active | |
Vendor:BitDefender Patch:No Platform:Windows Summary:- CVSS Score:- Credits:cobra | ||||||
| 2023 | Softing edgeConnector | Current | Denial-of-Service | High | Killed | |
Vendor:Siemens Patch:Yes Platform:- Summary:- CVSS Score:- Credits:hayicle | cobra | ||||||
| 2023 | Triangle Works | Current | Pre-auth Code Execution | Critical | Killed | |
Vendor:Microworks Patch:Yes Platform:- Summary:- CVSS Score:- Credits:bibo | hayicle | ahihi | ||||||
| 2023 | Firefox / TOR Browser RCE | Current | Code Execution | Critical | Killed | |
Vendor:Mozilla Patch:Yes Platform:Firefox Summary:- CVSS Score:- Credits:N/A | ||||||
| 2022 | Windows LPE #3 | Current | Local Privlege Escalation | Critical | Killed | |
Vendor:Microsoft Patch:Yes Platform:Windows Summary:- CVSS Score:- Credits:N/A | ||||||
| 2022 | Windows LPE #2 | Current | Local Privlege Escalation | Critical | Killed | |
Vendor:Microsoft Patch:Yes Platform:Windows Summary:- CVSS Score:- Credits:N/A | ||||||
| 2022 | Windows LPE | Current | Local Privlege Escalation | Critical | Killed | |
Vendor:Microsoft Patch:Yes Platform:Windows Summary:- CVSS Score:- Credits:N/A | ||||||
| 2021 | Yandex | Current | Theft of Sensitive Data | High | Killed | |
Vendor:Yandex Patch:No Platform:Android Summary:- CVSS Score:- Credits:z22 | ||||||
| 2021 | Yandex Browser | Current | Theft of Sensitive Data | High | Killed | |
Vendor:Yandex Patch:No Platform:Android Summary:- CVSS Score:- Credits:z22 | ||||||
| 2021 | ADManager Plus | Current | Code Execution #15 | Critical | Killed | |
Vendor:Manage Engine Patch:No Platform:Windows Summary:- CVSS Score:- Credits:bmtd | ||||||
| 2021 | ADManager Plus | Current | Code Execution #14 | Critical | Killed | |
Vendor:Manage Engine Patch:No Platform:Windows Summary:- CVSS Score:- Credits:bmtd | ||||||
| 2021 | ADManager Plus | < 7111 | Code Execution #13 | Critical | Killed | |
Vendor:Manage Engine Patch:Yes Platform:Windows Summary:- CVSS Score:- Credits:bmtd | ||||||
| 2021 | ADManager Plus | < 7111 | Authentication Bypass | High | Killed | |
Vendor:Manage Engine Patch:Yes Platform:Windows Summary:- CVSS Score:- Credits:hayicle | ||||||
| 2021 | ADManager Plus | < 7111 | Code Execution #12 | Critical | Killed | |
Vendor:Manage Engine Patch:Yes Platform:Windows Summary:- CVSS Score:- Credits:m3 | ||||||
| 2021 | ADManager Plus | < 7111 | Code Execution #11 | Critical | Killed | |
Vendor:Manage Engine Patch:Yes Platform:Windows Summary:- CVSS Score:- Credits:m3 | ||||||
| 2021 | ADManager Plus | < 7111 | Code Execution #10 | Critical | Killed | |
Vendor:Manage Engine Patch:Yes Platform:Windows Summary:- CVSS Score:- Credits:m3 | ||||||
| 2021 | ADManager Plus | < 7111 | Code Execution #9 | Critical | Killed | |
Vendor:Manage Engine Patch:Yes Platform:Windows Summary:- CVSS Score:- Credits:m3 | ||||||
| 2021 | ADManager Plus | < 7111 | Code Execution #8 | Critical | Killed | |
Vendor:Manage Engine Patch:Yes Platform:Windows Summary:- CVSS Score:- Credits:m3 | ||||||
| 2021 | ADManager Plus | < 7111 | Code Execution #7 | Critical | Killed | |
Vendor:Manage Engine Patch:Yes Platform:Windows Summary:- CVSS Score:- Credits:qbao | ||||||
| 2021 | ADManager Plus | < 7111 | Code Execution #6 | Critical | Killed | |
Vendor:Manage Engine Patch:Yes Platform:Windows Summary:- CVSS Score:- Credits:ncd | ||||||
| 2021 | ADManager Plus | < 7111 | Code Execution #5 | Critical | Killed | |
Vendor:Manage Engine Patch:Yes Platform:Windows Summary:- CVSS Score:- Credits:ncd | ||||||
| 2021 | ADManager Plus | < 7111 | Code Execution #4 | Critical | Killed | |
Vendor:Manage Engine Patch:Yes Platform:Windows Summary:- CVSS Score:- Credits:ncd | ||||||
| 2021 | ADManager Plus | < 7111 | Code Execution #3 | Critical | Killed | |
Vendor:Manage Engine Patch:Yes Platform:Windows Summary:- CVSS Score:- Credits:ncd | ||||||
| 2021 | ADManager Plus | < 7111 | Code Execution #2 | Critical | Killed | |
Vendor:Manage Engine Patch:Yes Platform:Windows Summary:- CVSS Score:- Credits:no3g | ||||||
| 2021 | ADManager Plus | < 7111 | Code Execution #1 | Critical | Killed | |
Vendor:Manage Engine Patch:Yes Platform:Windows Summary:- CVSS Score:- Credits:z22 | ||||||
| 2021 | ADManager Plus | < 7111 | Pre-auth Code Execution #3 | Critical | Killed | |
Vendor:Manage Engine Patch:Yes Platform:Windows Summary:- CVSS Score:- Credits:bmtd | ||||||
| 2021 | ADManager Plus | < 7111 | Pre-auth Code Execution #2 | Critical | Killed | |
Vendor:Manage Engine Patch:Yes Platform:Windows Summary:- CVSS Score:- Credits:bmtd | ||||||
| 2021 | ADManager Plus | < 7111 | Pre-auth Code Execution #1 | Critical | Killed | |
Vendor:Manage Engine Patch:Yes Platform:Windows Summary:- CVSS Score:- Credits:bmtd | ||||||
| 2021 | V-Key App Protection | Current | Security Bypass | High | Killed | |
Vendor:V-Key Patch:- Platform:IOS Summary:- CVSS Score:- Credits:hayicle | bmtd | ||||||
| 2019 | McAfee Total Protection | 16 | Privilege Escalation | Critical | Killed | |
Vendor:McAfee Patch:No Platform:Windows Summary:- CVSS Score:- Credits:pdnx00 | nixspl0it | ||||||
| 2017 | MalwareBytes | 3.0.4 - 3.2.x | Code Execution | Critical | Killed | |
Vendor:Malwarebytes Patch:Yes Platform:Windows Summary:- CVSS Score:- Credits:pdnx00 | nixspl0it | ||||||
| 2017 | Firefox Quantum | < 58 | Code Execution | Critical | Killed | |
Vendor:Mozilla Patch:Yes Platform:Windows Summary:- CVSS Score:- Credits:pdnx00 | nixspl0it | ||||||
| 2017 | 7z | > 16 | Code Execution | Critical | Killed | |
Vendor:7z Patch:No Platform:Windows / Linux Summary:- CVSS Score:- Credits:pdnx00 | nixspl0it | ||||||
| 2017 | PeaZip | > 6.4 | Code Execution | Critical | Killed | |
Vendor:- Patch:No Platform:Windows Summary:- CVSS Score:- Credits:pdnx00 | nixspl0it | ||||||
| 2017 | PowerArchiver | > 16.1 | Code Execution | Critical | Killed | |
Vendor:ConeXware Patch:No Platform:Windows Summary:- CVSS Score:- Credits:pdnx00 | nixspl0it | ||||||
| 2016 | Internet Explorer | < 11 | Code Execution | Critical | Killed | |
Vendor:Microsoft Patch:No Platform:Windows Summary:- CVSS Score:- Credits:nixspl0it | ||||||
| 2015 | Open WebMail | 2.52 | Local File Inclusion | Medium | Killed | |
Vendor:Open WebMail Patch:No Platform:Linux Summary:- CVSS Score:- Credits:xelenonz | ||||||
| 2015 | Open WebMail | 2.52 | Remote Code Execution | Critical | Killed | |
Vendor:Open WebMail Patch:No Platform:Linux Summary:- CVSS Score:- Credits:xelenonz | ||||||
| 2015 | Open WebMail | 2.52 | Privilege Escalation | Critical | Killed | |
Vendor:Open WebMail Patch:No Platform:Linux Summary:- CVSS Score:- Credits:xelenonz | ||||||
| 2015 | McAfee Agent EPO | N/A | Arbitrary File Reading | High | Killed | |
Vendor:McAfee Patch:Yes Platform:Windows Summary:- CVSS Score:- Credits:pdnx00 | ||||||
| 2013 | Freewill Gold Trading | N/A | Privilege Escalation | Critical | Killed | |
Vendor:Freewill Patch:Yes Platform:Linux Summary:- CVSS Score:- Credits:pdnx00 | ||||||
| 2013 | Freewill Gold Trading | N/A | Code Injection | Critical | Killed | |
Vendor:Freewill Patch:Yes Platform:Linux Summary:- CVSS Score:- Credits:xelenonz | ||||||
| 2013 | SabreAMF | 1.4 | XML External Entity | High | Killed | |
Vendor:Rooftop Patch:No Platform:Linux Summary:- CVSS Score:- Credits:xelenonz | ||||||
| 2009 | CPanel | 11.24.5-RELEASE | Arbitrary File Viewing | Medium | Killed | |
Vendor:cPanel Patch:Yes Platform:Linux Summary:- CVSS Score:- Credits:pdnx00 | ||||||
| 2009 | CPanel | 11.24.5-RELEASE | Privilege Escalation | Critical | Killed | |
Vendor:cPanel Patch:No Platform:Linux Summary:- CVSS Score:- Credits:pdnx00 | ||||||
| 2009 | CPanel | 11.24.5-RELEASE | Root Privilege Escalation | Critical | Killed | |
Vendor:cPanel Patch:Yes Platform:Linux Summary:- CVSS Score:- Credits:pdnx00 | ||||||
| 2008 | Belkin Router | F5D8233-4 V3, firmware 3.01.29 | Admin Remote Access | High | Killed | |
Vendor:Belkin Patch:Yes Platform:Linux Summary:- CVSS Score:- Credits:pdnx00 | ||||||
| 2007 | PHP Groupware | N/A | Code Injection | Critical | Killed | |
Vendor:Portico Estate Patch:Yes Platform:Windows / Linux Summary:- CVSS Score:- Credits:pdnx00 | ||||||
| 2006 | D-Link/Cipherium Interet Hotspot (Embedded System) | Bonalinx W-1300, firmware 1.5 | Code Execution | Critical | Killed | |
Vendor:D-link Patch:Yes Platform:Linux Summary:- CVSS Score:- Credits:pdnx00 | ||||||
| 2005 | Sawmill Log Analyzer | 7.0.X, < 7.1.7 | Arbitrary File Viewing | Medium | Killed | |
Vendor:Sawmill Patch:Yes Platform:Windows / Linux Summary:- CVSS Score:- Credits:pdnx00 | ||||||
| 2005 | Sawmill Log Analyzer | 7.0.X, < 7.1.6 | Arbitrary Directory Browsing | Medium | Killed | |
Vendor:Sawmill Patch:Yes Platform:Windows / Linux Summary:- CVSS Score:- Credits:pdnx00 | ||||||
| 2005 | Sawmill Log Analyzer | 7.0.X, < 7.1.6 | Code Execution | Critical | Killed | |
Vendor:Sawmill Patch:Yes Platform:Windows / Linux Summary:- CVSS Score:- Credits:pdnx00 | ||||||