Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
3192 articles · 168075 vulns · 37/41 feeds (7d)

Trending Vulnerabilities

Top vulnerabilities ranked by news velocity, CISA KEV status, EPSS exploitation probability, and independent source coverage.

1
7.8
linux · CVE-2026-31431 — crypto: algif_aead - Revert to operating out-of-placeKEVEXPLOITEDPATCHED
linux_kernel· CVSS 7.8
117🔥
84 art.
0
Apr 22, 2026
2
8.8
linux · CVE-2026-43284 — xfrm: esp: avoid in-place decrypt on shared skb fragsKEVEXPLOITEDPATCHED
linux_kernel· CVSS 8.8
112🔥
41 art.
0
May 8, 2026
3
7.8
linux · CVE-2026-43500 — rxrpc: Also unshare DATA/RESPONSE packets when paged frags are presentKEVEXPLOITEDPATCHED
linux_kernel· CVSS 7.8
106🔥
28 art.
0
May 11, 2026
4
10.0
ui · CVE-2026-34908 — CVE-2026-34908: A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi OS deKEVEXPLOITEDPATCHED
unifi_os_server· CVSS 10.0· CWE-284
97
9 art.
0
May 22, 2026
5
—
ptc · CVE-2026-12569 — Remote Code Execution (RCE) vulnerability in Windchill PDMlinkEXPLOITEDPATCHED
flexplm· CWE-20
96
8 art.
0
Jun 18, 2026
6
10.0
ui · CVE-2026-34909 — CVE-2026-34909: A malicious actor with access to the network could exploit a Path Traversal vulnerability found in UniFi OS devices to aKEVEXPLOITEDPATCHED
unifi_os_server· CVSS 10.0· CWE-22
92
5 art.
0
May 22, 2026
7
7.1
mappress · CVE-2026-56011 — WordPress MapPress Maps for WordPress plugin <= 2.97.3 - Cross Site Scripting (XSS) vulnerabilityKEVEXPLOITED
mappress maps for wordpress· CVSS 7.1· CWE-79
81
1 art.
0
Jun 26, 2026
8
7.1
linux · CVE-2026-46333 — ptrace: slightly saner 'get_dumpable()' logicEXPLOITEDPATCHED
kernel· CVSS 7.1· CWE-362
74
19 art.
0
May 15, 2026
9
9.2
libssh2 · CVE-2026-55200 — libssh2 - Out-of-Bounds Write via Unchecked packet_length in transport.cEXPLOITEDPATCHED
libssh2· CVSS 9.2· CWE-680
74
8 art.
0
Jun 17, 2026
10
8.6
cis · CVE-2026-20230 — CVE-2026-20230: A vulnerability in Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session MaEXPLOITEDPATCHED
unified_communications_manager· CVSS 8.6· CWE-918
74
19 art.
0
Jun 3, 2026
11
7.8
cis · CVE-2026-20245 — Cisco Catalyst SD-WAN Controller Authenticated Privilege Escalation VulnerabilityEXPLOITEDPATCHED
catalyst_sd-wan_manager· CVSS 7.8· CWE-116
74
21 art.
0
Jun 4, 2026
12
9.9
langflow · CVE-2026-55255 — Langflow: IDOR Vulnerability in `/api/v1/responses` Endpoint Allows Authenticated Attackers to Access Another User's FlowKEVEXPLOITEDPATCHED
langflow· CVSS 9.9· CWE-639
69
2 art.
0
Jun 19, 2026
13
7.5
gpac project · CVE-2025-60474 — CVE-2025-60474: A buffer overflow in the gf_media_import function (/media_tools/av_parsers.c) of GPAC Project/MP4Box before 26.02.0 alloEXPLOITED
mp4box· CVSS 7.5
68
2 art.
0
Jun 24, 2026
14
8.8
google · CVE-2026-13033 — CVE-2026-13033: Out of bounds read and write in Blink>InterestGroups in Google Chrome prior to 149.0.7827.197 allowed a remote attacker EXPLOITEDPATCHED
chrome· CVSS 8.8· CWE-125
65
5 art.
0
Jun 24, 2026
15
8.8
google · CVE-2026-13038 — CVE-2026-13038: Use after free in Autofill in Google Chrome on Windows prior to 149.0.7827.197 allowed a remote attacker to execute arbiEXPLOITEDPATCHED
chrome· CVSS 8.8· CWE-416
65
5 art.
0
Jun 24, 2026
16
7.8
linux · CVE-2026-46300 — net: skbuff: preserve shared-frag marker during coalescingEXPLOITEDPATCHED
linux_kernel· CVSS 7.8
64
19 art.
0
May 13, 2026
17
8.8
google · CVE-2026-13031 — CVE-2026-13031: Use after free in Blink in Google Chrome prior to 149.0.7827.197 allowed a remote attacker to execute arbitrary code insEXPLOITEDPATCHED
chrome· CVSS 8.8· CWE-416
62
4 art.
0
Jun 24, 2026
18
7.5
google · CVE-2026-13029 — CVE-2026-13029: Use after free in Web Authentication in Google Chrome prior to 149.0.7827.197 allowed an attacker who convinced a user tEXPLOITEDPATCHED
chrome· CVSS 7.5· CWE-416
62
4 art.
0
Jun 24, 2026
19
8.8
google · CVE-2026-13026 — CVE-2026-13026: Use after free in Digital Credentials in Google Chrome on Mac prior to 149.0.7827.197 allowed a remote attacker to potenEXPLOITEDPATCHED
chrome· CVSS 8.8· CWE-416
62
4 art.
0
Jun 24, 2026
20
8.3
google · CVE-2026-13025 — CVE-2026-13025: Race in DevTools in Google Chrome prior to 149.0.7827.197 allowed a remote attacker who had compromised the renderer proEXPLOITEDPATCHED
chrome· CVSS 8.3· CWE-20
62
4 art.
0
Jun 24, 2026
21
8.8
google · CVE-2026-13036 — CVE-2026-13036: Use after free in Blink in Google Chrome prior to 149.0.7827.197 allowed a remote attacker to execute arbitrary code insEXPLOITEDPATCHED
chrome· CVSS 8.8· CWE-416
62
4 art.
0
Jun 24, 2026
22
8.8
google · CVE-2026-13035 — CVE-2026-13035: Use after free in Bluetooth in Google Chrome on Mac prior to 149.0.7827.197 allowed a remote attacker to execute arbitraEXPLOITEDPATCHED
chrome· CVSS 8.8· CWE-416
62
4 art.
0
Jun 24, 2026
23
8.8
google · CVE-2026-13027 — CVE-2026-13027: Use after free in FileSystem in Google Chrome prior to 149.0.7827.197 allowed a remote attacker to potentially exploit hEXPLOITEDPATCHED
chrome· CVSS 8.8· CWE-416
62
4 art.
0
Jun 24, 2026
24
7.5
gpac project · CVE-2025-60467 — CVE-2025-60467: A use-after-free in the gf_filter_pid_inst_swap_delete_task function (/filter_core/filter_pid.c) of GPAC Project/MP4Box EXPLOITED
mp4box· CVSS 7.5
61
2 art.
0
Jun 24, 2026
25
7.5
apache · CVE-2026-49486 — Apache Airflow FTP provider: FTP Provider does not protect FTPS data channel (missing PROT_P)EXPLOITEDPATCHED
apache-airflow-providers-ftp· CVSS 7.5· CWE-319
61
3 art.
0
Jun 26, 2026
26
8.2
jqlang · CVE-2026-39979 — jq: Out-of-Bounds Read in jv_parse_sized() Error Formatting for Non-NUL-Terminated Counted BuffersEXPLOITEDPATCHED
jq· CVSS 8.2· CWE-125
61
5 art.
0
Apr 13, 2026
27
7.8
gpac project · CVE-2025-60464 — CVE-2025-60464: A use-after-free in the gf_sei_load_from_state_internal function (/filters/sei_load.c) of GPAC Project/MP4Box before 26.EXPLOITEDPATCHED
mp4box· CVSS 7.8
60
2 art.
0
Jun 25, 2026
28
9.1
flowi · CVE-2025-71327 — Flowise - Authentication Bypass via Unprotected Registration EndpointEXPLOITEDPATCHED
flowise· CVSS 9.1· CWE-306
59
2 art.
0
Jun 25, 2026
29
9.8
flowi · CVE-2025-71334 — Flowise - Arbitrary File Access via Missing Chat Flow ID ValidationEXPLOITEDPATCHED
flowise· CVSS 9.8· CWE-73
59
2 art.
0
Jun 25, 2026
30
10.0
flowi · CVE-2025-71338 — Flowise - Arbitrary File Write to Remote Code Execution via document-store APIEXPLOITEDPATCHED
flowise· CVSS 10.0· CWE-73
59
2 art.
0
Jun 25, 2026
31
—
google · CVE-2026-13022 — CVE-2026-13022: Inappropriate implementation in Autofill in Google Chrome prior to 149.0.7827.197 allowed a remote attacker who had compEXPLOITEDPATCHED
chrome
58
4 art.
0
Jun 24, 2026
32
8.3
google · CVE-2026-13281 — CVE-2026-13281: Integer overflow in Mojo in Google Chrome prior to 149.0.7827.201 allowed a remote attacker who had compromised the rendEXPLOITEDPATCHED
chrome· CVSS 8.3· CWE-472
58
4 art.
0
Jun 25, 2026
33
7.1
jqlang · CVE-2026-49839 — jq --rawfile invalid-state reuse after String too long causes heap-buffer-overflowEXPLOITEDPATCHED
jq· CVSS 7.1· CWE-787
58
2 art.
0
Jun 25, 2026
34
7.5
perl · CVE-2026-11702 — Bytes::Random::Secure::Tiny versions through 1.011 for Perl share internal state across forked processesEXPLOITEDPATCHED
bytes::random::secure::secure::tiny· CVSS 7.5· CWE-335
57
2 art.
0
Jun 26, 2026
35
8.8
linux · CVE-2026-43503 — net: skbuff: propagate shared-frag marker through frag-transfer helpersEXPLOITEDPATCHED
linux_kernel· CVSS 8.8· CWE-20
57
9 art.
0
May 23, 2026
36
7.5
gravity forms · CVE-2026-4020 — Gravity SMTP <= 2.1.4 - Unauthenticated Sensitive Information Exposure via REST APIKEVEXPLOITED
gravity smtp· CVSS 7.5· CWE-200
57
4 art.
0
Mar 31, 2026
37
7.5
perl · CVE-2026-11625 — Bytes::Random::Secure versions through 0.29 for Perl share internal state across forked processesEXPLOITEDPATCHED
bytes::random::secure· CVSS 7.5· CWE-335
57
2 art.
0
Jun 26, 2026
38
7.5
dragonflydb · CVE-2026-54341 — Dragonfly: RESTORE operations may crash the serverEXPLOITEDPATCHED
dragonfly· CVSS 7.5· CWE-125
55
1 art.
0
Jun 26, 2026
39
9.8
paytium · CVE-2026-56030 — WordPress Paytium plugin <= 5.0.2 - Privilege Escalation vulnerabilityEXPLOITED
paytium· CVSS 9.8· CWE-266
55
1 art.
0
Jun 26, 2026
40
10.0
budiba · CVE-2026-54350 — Budibase: Anonymous NoSQL operator injection via published-app query templatesEXPLOITEDPATCHED
budiba· CVSS 10.0· CWE-89
55
2 art.
0
Jun 23, 2026
41
5.5
GPAC Project · CVE-2025-60473 — CVE-2025-60473: A NULL pointer dereference in the gf_filter_in_parent_chain function (/filter_core/filter_pid.c) of GPAC Project/MP4Box EXPLOITED
n/a· CVSS 5.5
55
2 art.
0
Jun 24, 2026
42
5.0
GPAC Project · CVE-2025-60466 — CVE-2025-60466: A use-after-free in the gf_filter_pid_get_packet function (/filter_core/filter_pid.c) of GPAC Project/MP4Box before 26.0EXPLOITED
n/a· CVSS 5.0
55
2 art.
0
Jun 24, 2026
43
5.3
broadcom · CVE-2026-40012 — Information about ECS zero scoped answers might leak to clients that use a specific ECSEXPLOITEDPATCHED
symantec endpoint security· CVSS 5.3
55
3 art.
0
Jun 25, 2026
44
9.8
dokan · CVE-2026-56033 — WordPress Dokan Pro plugin <= 5.0.4 - Privilege Escalation vulnerabilityEXPLOITED
dokan pro· CVSS 9.8· CWE-266
55
1 art.
0
Jun 26, 2026
45
8.3
wso2 · CVE-2026-2053 — Unauthenticated Server-Side Request Forgery via WS-Addressing in WSO2 API ManagerEXPLOITEDPATCHED
api· CVSS 8.3· CWE-918
55
2 art.
0
Jun 26, 2026
46
6.1
gpac project · CVE-2025-60465 — CVE-2025-60465: A use-after-free in the gf_filter_pid_inst_swap function (/filter_core/filter_pid.c) of GPAC Project/MP4Box before 26.02EXPLOITEDPATCHED
mp4box· CVSS 6.1
55
2 art.
0
Jun 25, 2026
47
6.8
google · CVE-2026-13282 — CVE-2026-13282: Use after free in Payments in Google Chrome on Android prior to 149.0.7827.201 allowed a local attacker to potentially eEXPLOITEDPATCHED
chrome· CVSS 6.8· CWE-416
54
4 art.
0
Jun 25, 2026
48
4.2
google · CVE-2026-13024 — CVE-2026-13024: Insufficient validation of untrusted input in Navigation in Google Chrome prior to 149.0.7827.197 allowed a remote attacEXPLOITEDPATCHED
chrome· CVSS 4.2· CWE-20
54
4 art.
0
Jun 24, 2026
49
9.8
buddyboss · CVE-2026-56032 — WordPress Buddyboss Platform plugin <= 3.0.4 - PHP Object Injection vulnerabilityEXPLOITED
buddyboss· CVSS 9.8· CWE-502
54
1 art.
0
Jun 26, 2026
50
5.3
google · CVE-2026-13023 — CVE-2026-13023: Uninitialized Use in GPU in Google Chrome prior to 149.0.7827.197 allowed a remote attacker who had compromised the rendEXPLOITEDPATCHED
chrome· CVSS 5.3· CWE-457
54
4 art.
0
Jun 24, 2026