Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4357 articles · 196326 vulns · 36/41 feeds (7d)

Trending Vulnerabilities

Top vulnerabilities ranked by news velocity, CISA KEV status, EPSS exploitation probability, and independent source coverage.

1
10.0
Microsoft · CVE-2026-69836 — Microsoft Entra ID Remote Code Execution VulnerabilityKEVEXPLOITEDPATCHED
Microsoft Entra· CVSS 10.0· CWE-502
129🔥
8 art.
0
Aug 20, 2026
2
9.8
trueconf · CVE-2026-72529 — CVE-2026-72529: A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions 5.3.X to 5.3.9, 5.4KEVEXPLOITEDPATCHED
trueconf_server· CVSS 9.8· CWE-306
100
4 art.
0
Aug 19, 2026
3
8.9
synacor · CVE-2026-73570 — CVE-2026-73570: A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp KEVEXPLOITEDPATCHED
zimbra_collaboration_suite· CVSS 8.9· CWE-78
94
6 art.
0
Aug 13, 2026
4
9.0
trueconf · CVE-2026-72530 — CVE-2026-72530: A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions 5.3.X to 5.3.9, 5.4KEVEXPLOITEDPATCHED
trueconf_server· CVSS 9.0· CWE-94
94
4 art.
0
Aug 19, 2026
5
8.8
citrix · CVE-2026-8451 — Insufficient input validation leading to memory overreadKEVEXPLOITEDPATCHED
netscaler_application_delivery_controller· CVSS 8.8· CWE-125
90
11 art.
0
Jun 30, 2026
6
9.3
lfprojects · CVE-2026-64849 — MLflow: Unauthenticated full-read SSRF in webhook delivery: _validate_webhook_url bypassed via unvalidated HTTP redirects (and DNS rebinding)KEVEXPLOITEDPATCHED
mlflow· CVSS 9.3· CWE-918
89
6 art.
0
Aug 17, 2026
7
9.8
apple · CVE-2026-65400 — CVE-2026-65400: An authentication issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.9, macOSKEVEXPLOITEDPATCHED
macos· CVSS 9.8· CWE-20
87
18 art.
0
Aug 6, 2026
8
9.1
microsoft · CVE-2026-55040 — Microsoft SharePoint Server Security Feature Bypass VulnerabilityKEVEXPLOITEDPATCHED
sharepoint_server· CVSS 9.1· CWE-1390
87
23 art.
0
Jul 14, 2026
9
10.0
gogs · CVE-2026-52813 — Gogs: Path Traversal in organization name results in RCE through Git hooksKEVEXPLOITEDPATCHED
gogs· CVSS 10.0· CWE-23
83
3 art.
0
Jun 23, 2026
10
9.8
vmware · CVE-2026-59310 — vCenter directory-traversal vulnerabilityKEVEXPLOITEDPATCHED
vcenter_server· CVSS 9.8· CWE-22
83
14 art.
0
Jul 30, 2026
11
—
ptc · CVE-2026-12569 — Remote Code Execution (RCE) vulnerability in Windchill PDMlinkKEVEXPLOITEDPATCHED
flexplm· CWE-20
82
16 art.
0
Jun 18, 2026
12
9.8
microsoft · CVE-2026-50522 — Microsoft SharePoint Remote Code Execution VulnerabilityKEVEXPLOITEDPATCHED
sharepoint_server· CVSS 9.8· CWE-502
80
12 art.
0
Jul 14, 2026
13
9.8
spip · CVE-2026-77806 — CVE-2026-77806: SPIP before 4.4.21 allows unauthenticated remote attackers to execute arbitrary code, as exploited in the wild in AugustKEVEXPLOITEDPATCHED
spip· CVSS 9.8· CWE-94
78
1 art.
0
Aug 21, 2026
14
7.0
microsoft · CVE-2026-68820 — Windows Ancillary Function Driver for WinSock Elevation of Privilege VulnerabilityKEVEXPLOITEDPATCHED
windows_10_1607· CVSS 7.0· CWE-416
73
21 art.
0
Aug 11, 2026
15
9.4
gitlab · CVE-2026-19478 — Improper Control of Generation of Code ('Code Injection') in GitLabPATCHED
gitlab· CVSS 9.4· CWE-94
71
13 art.
0
Aug 17, 2026
16
9.8
SPIP · CVE-2026-77647 — CVE-2026-77647: SPIP before 4.4.20 allows unauthenticated remote attackers to execute arbitrary code, as exploited in the wild in AugustKEVEXPLOITEDPATCHED
SPIP· CVSS 9.8· CWE-94
71
1 art.
0
Aug 20, 2026
17
9.8
geotools · CVE-2026-76904 — GeoTools has unauthenticated SQL injection in the jsonArrayContains filter function against PostGIS layersKEVEXPLOITEDPATCHED
geotools· CVSS 9.8· CWE-89
70
1 art.
0
Aug 21, 2026
18
7.8
microsoft · CVE-2026-45586 — Windows Collaborative Translation Framework (CTFMON) Elevation of Privilege VulnerabilityKEVEXPLOITEDPATCHED
windows_10_1607· CVSS 7.8· CWE-59
65
12 art.
0
Jun 9, 2026
19
8.8
linux · CVE-2026-53359 — KVM: x86: Fix shadow paging use-after-free due to unexpected roleEXPLOITEDPATCHED
linux_kernel· CVSS 8.8
63
25 art.
0
Jul 4, 2026
20
7.8
linux · CVE-2026-46331 — net/sched: fix pedit partial COW leading to page cache corruptionEXPLOITEDPATCHED
linux_kernel· CVSS 7.8
63
18 art.
0
Jun 16, 2026
21
—
rubygems · CVE-2026-66066 — Action Pack: Possible arbitrary file read and remote code execution in Active Storage variant processingPATCHED
activestorage· CWE-1188
61
16 art.
0
Jul 30, 2026
22
7.8
microsoft · CVE-2026-50656 — Microsoft Defender Elevation of Privilege VulnerabilityEXPLOITEDPATCHED
malware_protection_engine· CVSS 7.8· CWE-59
60
22 art.
0
Jun 16, 2026
23
8.6
cis · CVE-2026-20349 — Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software Remote Access SSL VPN Denial of Service Vulnerability
adaptive_security_appliance_software· CVSS 8.6· CWE-244
56
12 art.
0
Aug 11, 2026
24
10.0
sap · CVE-2026-58231 — Improper Authorization in SAP Commerce Cloud (Data Hub Adapter)KEVEXPLOITED
sap commerce cloud (data hub adapter)· CVSS 10.0· CWE-94
56
12 art.
0
Aug 11, 2026
25
—
gnu · CVE-2026-41992 — Global Buffer Overflow in GNU gzipEXPLOITEDPATCHED
gzip· CWE-126
55
4 art.
0
Jun 29, 2026
26
7.8
linux · CVE-2026-64600 — xfs: resample the data fork mapping after cycling ILOCKEXPLOITEDPATCHED
linux_kernel· CVSS 7.8
55
18 art.
0
Jul 23, 2026
27
7.5
widgetfactory · CVE-2026-48907 — Joomla Extension - joomlacontenteditor.net - Remote Code Execution in JCE extension for Joomla < 2.9.99.5KEVEXPLOITED
jce· CVSS 7.5· CWE-284
53
8 art.
0
Jun 5, 2026
28
—
citrix · CVE-2026-19490 — NetScaler ADC and NetScaler Gateway Security Bulletin for CVE-2026-19490
adc
53
10 art.
0
Aug 19, 2026
29
10.0
aresit · CVE-2026-73343 — WordPress WP Compress plugin < 7.20.01 - Remote Code Execution (RCE) vulnerabilityKEVEXPLOITEDPATCHED
wp compress· CVSS 10.0· CWE-94
52
1 art.
0
Aug 18, 2026
30
8.8
openssl · CVE-2026-45447 — Heap Use-After-Free in the PKCS7_verify() FunctionEXPLOITEDPATCHED
openssl· CVSS 8.8· CWE-416
51
17 art.
0
Jun 9, 2026
31
7.8
linux · CVE-2026-46242 — eventpoll: fix ep_remove struct eventpoll / struct file UAFEXPLOITEDPATCHED
linux_kernel· CVSS 7.8
50
13 art.
0
May 30, 2026
32
7.5
perl · CVE-2026-48962 — IO::Compress versions before 2.220 for Perl can execute arbitrary code in File::GlobMapper via an attacker-controlled output globEXPLOITEDPATCHED
io::compress· CVSS 7.5· CWE-95
50
8 art.
0
May 27, 2026
33
9.6
kata-containers · CVE-2026-50540 — Kata Containers: Config Path Annotation Arbitrary File Loading
kata-containers· CVSS 9.6· CWE-20
49
3 art.
0
Aug 7, 2026
34
—
immutable-js · CVE-2026-59880 — Immutable.js: Hash-collision algorithmic complexity denial of service in Immutable.Map/SetEXPLOITEDPATCHED
immutable· CWE-400
49
3 art.
0
Jul 8, 2026
35
7.5
immutable-js · CVE-2026-59879 — Immutable.js `List` 32-bit trie overflow → unrecoverable DoSEXPLOITEDPATCHED
immutable· CVSS 7.5· CWE-190
49
3 art.
0
Jul 8, 2026
36
—
apache · CVE-2026-53434 — Apache Tomcat: Invalid CRL configuration doesn't trigger failure for FFM ConnectorEXPLOITEDPATCHED
tomcat· EPSS 0.00· CWE-390
48
5 art.
0
Jun 29, 2026
37
7.8
linux · CVE-2026-53366 — ipv4: account for fraggap on the paged allocation pathEXPLOITEDPATCHED
linux_kernel· CVSS 7.8
48
14 art.
0
Jul 16, 2026
38
7.5
isaacs · CVE-2026-59873 — node-tar: Decompression/parse DoS via unlimited inputEXPLOITEDPATCHED
tar· CVSS 7.5· CWE-770
47
6 art.
0
Jul 8, 2026
39
7.5
citrix · CVE-2026-8452 — Memory overflow vulnerability leading to unpredictable or erroneous behavior and Denial of ServiceKEVEXPLOITEDPATCHED
netscaler_application_delivery_controller· CVSS 7.5· CWE-119
47
7 art.
0
Jun 30, 2026
40
10.0
metaba · CVE-2026-72898 — Metabase SQL injection via password reset endpointKEVEXPLOITEDPATCHED
metabase· CVSS 10.0· CWE-89
47
3 art.
0
Aug 10, 2026
41
7.1
linux · CVE-2026-63833 — ntfs3: reject direct userspace writes to reserved $LX* xattrsPATCHED
linux kernel· CVSS 7.1
46
6 art.
0
Jul 19, 2026
42
8.1
jetmonsters · CVE-2026-73400 — WordPress Restaurant Menu by MotoPress plugin <= 2.4.11 - Local File Inclusion vulnerabilityKEVEXPLOITED
restaurant menu by motopress· CVSS 8.1· CWE-98
46
1 art.
0
Aug 18, 2026
43
—
graham ollis · CVE-2026-48959 — IO::Uncompress::Unzip versions before 2.220 for Perl allow CPU exhaustion via per-byte read loop in fastForwardEXPLOITEDPATCHED
io::uncompress::unzip· CWE-407
45
6 art.
0
May 27, 2026
44
—
linux · CVE-2026-53306 — tty: hvc_iucv: fix off-by-one in number of supported devicesEXPLOITEDPATCHED
linux_kernel
45
9 art.
0
Jun 26, 2026
45
7.8
Linux · CVE-2026-64531 — net: openvswitch: reject oversized nested action attrsPATCHED
Linux· CVSS 7.8
45
16 art.
0
Jul 27, 2026
46
9.8
ibm · CVE-2026-14446 — IBM WebSphere Application Server is affected by a privilege escalationPATCHED
websphere_application_server· CVSS 9.8· CWE-306
45
6 art.
0
Jul 28, 2026
47
—
linux · CVE-2026-53291 — ALSA: hda/conexant: Fix missing error check for jack detectionEXPLOITEDPATCHED
linux_kernel
45
6 art.
0
Jun 26, 2026
48
8.8
linux · CVE-2026-53360 — KVM: SEV: Require in-GHCB scratch area if GHCB v2+ is in useEXPLOITEDPATCHED
linux_kernel· CVSS 8.8
45
8 art.
0
Jul 4, 2026
49
10.0
sonicwall · CVE-2026-15409 — CVE-2026-15409: A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A KEVEXPLOITEDPATCHED
sma6210_firmware· CVSS 10.0· CWE-918
45
25 art.
0
Jul 14, 2026
50
9.8
linux · CVE-2026-53309 — ocfs2/dlm: fix off-by-one in dlm_match_regions() region comparisonEXPLOITEDPATCHED
linux_kernel· CVSS 9.8
45
6 art.
0
Jun 26, 2026