Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4501 articles · 223832 vulns · 37/41 feeds (7d)

Latest Security News

Recently analyzed articles from 41 RSS feeds across official advisories, government CERTs, security research, and community sources.

Tier A: Official
Tier B: Gov CERT
Tier C: Research
Tier D: News
Tier E: Community
Status:
AllAnalyzedQueuedSignal Only
C
CVE-2026-101083 | PMWeb v7.x/v8.x/v2025.x encryptionhelper.dll information disclosure
VulDB·6h ago·cve_linking
C
CVE-2026-101082 | PMWeb 7.x/8.x/2025.x downloader.aspx FullFileName/FileName path traversal
VulDB·6h ago·cve_linking
C
CVE-2026-101081 | D-Link DI-8400 16.07 Web Administration Service menu_nat_more.asp menu_nat_more_asp opt stack-based overflow
VulDB·7h ago·cve_linking
C
CVE-2026-101080 | Tencent AI-Infra-Guard up to 4.5.2/4.6.2 File Access dir_actions.py startsWith path traversal (Issue 538)
VulDB·7h ago·cve_linking
C
CVE-2026-101079 | agentverus agentverus-scanner up to 0.8.1 context.js isSecurityDefenseSkill reliance on untrusted inputs in a security decision (Issue 28)
VulDB·7h ago·cve_linking
C
CVE-2026-101078 | deepseek-ai deepseek-harness up to 0.1.7-rc.2 Landlock Backend profiles.ts isolation
VulDB·7h ago·cve_linking
C
CVE-2026-101077 | Netcore NR289-GE 1.4.5102 boa_temp process_request missing authentication
VulDB·7h ago·cve_linking
C
CVE-2026-101076 | Netcore NR289-GE 1.4.5102 CGI /set_ntp_server_ip.cgi system ntp_ip os command injection
VulDB·7h ago·cve_linking
C
CVE-2026-101075 | Netcore NR289-GE 1.4.5102 Location Time /location_time.cgi system mac os command injection
VulDB·7h ago·cve_linking
C
CVE-2026-101074 | Netcore NR289-GE 1.4.5102 Authentication /bin/boa password-check Username stack-based overflow
VulDB·7h ago·cve_linking
C
CVE-2026-101073 | Netcore NR289-GE 1.4.5102 CGI Dispatcher /bin/boa improper authentication
VulDB·7h ago·cve_linking
C
CVE-2026-101072 | Netcore NR289-GE 1.4.5102 CGI /ap_ip.cgi system ip os command injection
VulDB·7h ago·cve_linking
C
CVE-2026-101071 | Acrel Electric Unet Web Service up to 20260814 Upload Endpoint upload File unrestricted upload
VulDB·8h ago·cve_linking
C
CVE-2026-101070 | dbgate up to 7.3.1 Files Endpoint runners.js files runid path traversal
VulDB·8h ago·cve_linking
C
CVE-2026-101069 | dbgate up to 7.3.1 Export databaseConnections.js exportModelSql outputFile path traversal
VulDB·8h ago·cve_linking
C
CVE-2026-101068 | dbgate up to 7.3.1 Create Connection Endpoint zipJsonLinesData.js zipJsonLinesData filePath path traversal
VulDB·8h ago·cve_linking
C
CVE-2026-101067 | dbgate up to 7.3.1 save-uploaded-file Endpoint files.js saveUploadedFile filePath/fileName path traversal
VulDB·8h ago·cve_linking
C
CVE-2026-101066 | dbgate up to 7.3.1 Archive Link Creation archive.js createLink linkedFolder path traversal
VulDB·8h ago·cve_linking
C
CVE-2026-101055 | Thinkware U3000 up to 1.02.04 TCP Service GET_STATUS wifi_info information disclosure
VulDB·9h ago·cve_linking
C
CVE-2026-101054 | Thinkware U3000 up to 1.02.04 TCP Service /tmp/wpa_supplicant.conf get_file access control
VulDB·9h ago·cve_linking
C
CVE-2026-101053 | Thinkware U3000 up to 1.02.04 TCP Service /tmp/wpa_supplicant.conf PUT_FILE path access control
VulDB·9h ago·cve_linking
C
CVE-2026-101052 | refly-ai refly up to 1.1.0 JWT Token app.config.ts hard-coded credentials
VulDB·9h ago·cve_linking
C
CVE-2026-101040 | Ricoh SP 330DN/SP 221/SP C252SF//Aficio SP 3500SF up to 20260813 HTTP Multipart Form-Data Parser denial of service
VulDB·11h ago·cve_linking
C
CVE-2026-101039 | FAST FAC1900R 20190827_2.0.2 devdiscover Service copy_msg_element stack-based overflow
VulDB·11h ago·cve_linking
C
CVE-2026-101038 | FAST FAC1200R 5.0_20201119_1.0.2 MmtAtePrase Parser stack-based overflow
VulDB·11h ago·cve_linking
C
CVE-2026-101037 | FAST FAC1200R 5.0_20201119_1.0.2 devdiscover Service parse_advertisement_frame stack-based overflow
VulDB·11h ago·cve_linking
C
CVE-2026-101036 | FLB-Music FLB-Music-Player 1.1.8/1.1.9/1.2.0/1.2.1 createParsedTrack.ts path.join path traversal
VulDB·11h ago·cve_linking
C
CVE-2026-101035 | aligungr UERANSIM up to 3.3.0 nr-gnb src/lib/nas/encode.cpp DecodePlainMmMessage uncaught exception
VulDB·11h ago·cve_linking
C
CVE-2026-101018 | dayrui XunruiCMS up to 4.7.2 Group Editing Home.php group_all_edit groupid sql injection
VulDB·14h ago·cve_linking
C
CVE-2026-101017 | Trusted Domain Project OpenDMARC up to 1.4.2 opendmarc_policy.c strcasecmp exceptional condition
VulDB·14h ago·cve_linking
C
CVE-2026-101016 | Trusted Domain Project OpenDMARC up to 1.4.2 opendmarc_policy.c opendmarc_policy_parse_dmarc fo/rf/ri/pct/sp/adkim/aspf/rua/ruf exceptional condition
VulDB·14h ago·cve_linking
C
CVE-2026-101015 | Trusted Domain Project OpenDMARC up to 1.4.2 policy.c improper validation of unsafe equivalence in input
VulDB·14h ago·cve_linking
C
CVE-2026-101014 | Trusted Domain Project OpenDMARC up to 1.4.2 DMARC Record Parser opendmarc_util.c opendmarc_util_cleanup off-by-one (ID 188)
VulDB·14h ago·cve_linking
C
CVE-2026-101013 | mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be updateresultdetails.php editid sql injection
VulDB·14h ago·cve_linking
C
CVE-2026-101012 | mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be makeresult.php makeid sql injection
VulDB·14h ago·cve_linking
C
CVE-2026-101011 | aaPanel BaoTa up to 11.8.0 Domain domainMod.py get_domain_status get sql injection
VulDB·14h ago·cve_linking
C
CVE-2026-101010 | aaPanel BaoTa up to 11.8.0 data.py getData log_type sql injection
VulDB·14h ago·cve_linking
C
CVE-2026-101009 | aaPanel BaoTa up to 11.8.0 Unzip panelTask.py panelTask.bt_task._unzip Password os command injection
VulDB·14h ago·cve_linking
C
CVE-2026-101008 | aaPanel BaoTa up to 11.8.0 File Merge files.py merge_split_file split_file_path command injection
VulDB·14h ago·cve_linking
C
CVE-2026-101007 | aaPanel BaoTa up to 11.8.0 Database Backup class/database.py InputSql Password os command injection
VulDB·14h ago·cve_linking
C
CVE-2026-101006 | Frappe HR up to 16.15.0 Permission Validation hrms/api/__init__.py employee authorization
VulDB·14h ago·cve_linking
C
CVE-2026-101005 | October CMS up to 4.3.4 SSRF Protection ResizeImages.php validateExternalImageHost server-side request forgery (GHSA-j2j7-7m99-6226)
VulDB·15h ago·cve_linking
C
CVE-2026-101004 | notionnext-org NotionNext up to 4.10.10 Authentication Guard pages/api/cache.js cleanCache token missing authentication
VulDB·15h ago·cve_linking
C
CVE-2026-101003 | Cesanta Mongoose up to 7.21 MQTT Broker main.c fn stack-based overflow
VulDB·15h ago·cve_linking
C
CVE-2026-101002 | Netcore NBR200V2 1.3.241127.071246 Tools Ping /usr/bin/network_tools system url os command injection
VulDB·15h ago·cve_linking
C
CVE-2026-101001 | Netcore NBR200V2 1.3.241127.071246 Web Management Interface network_tools eval QUERY_STRING os command injection
VulDB·15h ago·cve_linking
C
CVE-2026-101000 | Netcore NBR100V2 1.3.240614.030928 ACL unauthenticated.json uci.apply section authorization
VulDB·15h ago·cve_linking
C
CVE-2026-100909 | OctoberCMS up to 4.1.19/4.2.25/4.3.4 ResizeImages.php getSourcePathForResize realSourcePath server-side request forgery (GHSA-2xmm-m4wv-3fjh)
VulDB·15h ago·cve_linking
C
CVE-2026-89102 | wolfSSL up to 5.9.2 OCSP Stapling wolfSSL_UseOCSPStaplingV2 certificate validation
VulDB·16h ago·cve_linking
C
CVE-2026-15442 | wolfSSL up to 5.9.2 TLS Shutdown wolfSSL_read use after free
VulDB·16h ago·cve_linking
Articles are automatically fetched from RSS feeds, pre-filtered for security relevance, and analyzed by LLM for vulnerability extraction. View feed sources