Zero Day Monitor
ZDM
Dashboard
Vulnerabilities
Trending
Zero-Days
News
About
Login
All types
CVE only
Pre-CVE only
CISA KEV only
All severities
Critical
High
Medium
Low
More filters
Trending
Newest
Urgent
Critical Only
Weekly Urgent
Weekly Trending
193,630 vulnerabilities total
10.0
Microsoft ·
CVE-2026-69836 —
Microsoft Entra ID Remote Code Execution Vulnerability
KEV
EXPLOITED
PATCHED
Microsoft Entra
· CVSS 10.0
· CWE-502
129
🔥
8 art.
0
Aug 20, 2026
7.8
linux ·
CVE-2026-31431 —
crypto: algif_aead - Revert to operating out-of-place
KEV
EXPLOITED
PATCHED
linux_kernel
· CVSS 7.8
100
91 art.
0
Apr 22, 2026
9.8
trueconf ·
CVE-2026-72529 —
CVE-2026-72529: A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions 5.3.X to 5.3.9, 5.4
KEV
EXPLOITED
PATCHED
trueconf_server
· CVSS 9.8
· CWE-306
100
4 art.
0
Aug 19, 2026
7.8
trueconf ·
CVE-2026-3502 —
TrueConf Client Update Integrity Verification Bypass
KEV
EXPLOITED
trueconf
· CVSS 7.8
· CWE-494
97
10 art.
1
Mar 30, 2026
9.0
trueconf ·
CVE-2026-72530 —
CVE-2026-72530: A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions 5.3.X to 5.3.9, 5.4
KEV
EXPLOITED
PATCHED
trueconf_server
· CVSS 9.0
· CWE-94
94
4 art.
0
Aug 19, 2026
8.9
synacor ·
CVE-2026-73570 —
CVE-2026-73570: A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp
KEV
EXPLOITED
PATCHED
zimbra_collaboration_suite
· CVSS 8.9
· CWE-78
94
6 art.
0
Aug 13, 2026
8.8
arm ·
CVE-2022-38181 —
The Arm Mali GPU kernel driver allows unprivileged users to access freed memory because GPU memory operations are mishandled. This affects Bifrost r0p0 through r38p1, and r39p0; Valhall r19p0 through
KEV
EXPLOITED
bifrost_gpu_kernel_driver
· CVSS 8.8
· CWE-416
90
1 art.
0
Oct 25, 2022
9.8
progress ·
CVE-2023-34362 —
In Progress MOVEit Transfer before 2021.0.6 (13.0.6), 2021.1.4 (13.1.4), 2022.0.4 (14.0.4), 2022.1.5 (14.1.5), and 2023.0.1 (15.0.1), a SQL injection vulnerability has been found in the MOVEit Transfe
KEV
EXPLOITED
PATCHED
moveit_cloud
· CVSS 9.8
· EPSS 0.94
· CWE-89
90
2 art.
0
Jun 2, 2023
8.8
citrix ·
CVE-2026-8451 —
Insufficient input validation leading to memory overread
KEV
EXPLOITED
PATCHED
netscaler_application_delivery_controller
· CVSS 8.8
· CWE-125
90
11 art.
0
Jun 30, 2026
9.3
lfprojects ·
CVE-2026-64849 —
MLflow: Unauthenticated full-read SSRF in webhook delivery: _validate_webhook_url bypassed via unvalidated HTTP redirects (and DNS rebinding)
KEV
EXPLOITED
PATCHED
mlflow
· CVSS 9.3
· CWE-918
89
6 art.
0
Aug 17, 2026
9.8
apple ·
CVE-2026-65400 —
CVE-2026-65400: An authentication issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.9, macOS
KEV
EXPLOITED
PATCHED
macos
· CVSS 9.8
· CWE-20
87
18 art.
0
Aug 6, 2026
9.1
microsoft ·
CVE-2026-55040 —
Microsoft SharePoint Server Security Feature Bypass Vulnerability
KEV
EXPLOITED
PATCHED
sharepoint_server
· CVSS 9.1
· CWE-1390
87
23 art.
0
Jul 14, 2026
7.5
siemens ·
CVE-2023-44487 —
CVE-2023-44487: The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many
KEV
EXPLOITED
PATCHED
simatic_s7-1500_cpu_1518f-4_pn\/dp_mfp_firmware
· CVSS 7.5
86
8 art.
0
Oct 10, 2023
9.8
vmware ·
CVE-2026-59310 —
vCenter directory-traversal vulnerability
KEV
EXPLOITED
PATCHED
vcenter_server
· CVSS 9.8
· CWE-22
83
14 art.
0
Jul 30, 2026
10.0
gogs ·
CVE-2026-52813 —
Gogs: Path Traversal in organization name results in RCE through Git hooks
KEV
EXPLOITED
PATCHED
gogs
· CVSS 10.0
· CWE-23
83
3 art.
0
Jun 23, 2026
8.1
f5 ·
CVE-2026-42945 —
NGINX ngx_http_rewrite_module vulnerability
KEV
EXPLOITED
PATCHED
dos
· CVSS 8.1
· CWE-122
83
30 art.
0
May 13, 2026
—
ptc ·
CVE-2026-12569 —
Remote Code Execution (RCE) vulnerability in Windchill PDMlink
KEV
EXPLOITED
PATCHED
flexplm
· CWE-20
82
16 art.
0
Jun 18, 2026
9.8
microsoft ·
CVE-2026-50522 —
Microsoft SharePoint Remote Code Execution Vulnerability
KEV
EXPLOITED
PATCHED
sharepoint_server
· CVSS 9.8
· CWE-502
80
12 art.
0
Jul 14, 2026
9.8
spip ·
CVE-2026-77806 —
CVE-2026-77806: SPIP before 4.4.21 allows unauthenticated remote attackers to execute arbitrary code, as exploited in the wild in August
KEV
EXPLOITED
PATCHED
spip
· CVSS 9.8
· CWE-94
78
1 art.
0
Aug 21, 2026
8.8
microsoft ·
CVE-2026-45659 —
Microsoft SharePoint Remote Code Execution Vulnerability
KEV
EXPLOITED
PATCHED
sharepoint_server
· CVSS 8.8
· CWE-502
78
17 art.
0
May 22, 2026
Load more