Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
2848 articles · 109425 vulns · 38/41 feeds (7d)
663
+74 today
Exploited (7d)
361
+75 today
Critical (7d)
1533
CISA KEV
26
Pre-CVE
2848
+554 today
Articles (7d)

Threat Briefing

Global

Loading...

About Zero Day Monitor

Open-source vulnerability intelligence for security teams. The platform scans 41 security feeds, analyzes articles with AI, and surfaces the threats that matter. Track trending CVEs, discover zero-days before they get a CVE ID, and monitor your vendor stack for supply-chain risks.

Trending
Ranked by source count
Zero-Days
Pre-CVE detection
Verification
Community-driven
Open Source
AGPL-3.0 licensed
Learn more about the projectSign in for personalized features

Vulnerabilities

9.8
ivanti · CVE-2026-1340 — CVE-2026-1340: A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution.KEVEXPLOITEDPATCHED
endpoint_manager_mobile· CVSS 9.8· CWE-94
144🔥
3 art.
0
Jan 29, 2026
9.1
fortinet · CVE-2026-35616 — CVE-2026-35616: A improper access control vulnerability in Fortinet FortiClientEMS 7.4.5 through 7.4.6 may allow an unauthenticated attaKEV
EXPLOITED
PATCHED
forticlientems· CVSS 9.1· CWE-284
134🔥
17 art.
0
Apr 4, 2026
8.8
google · CVE-2026-5281 — CVE-2026-5281: Use after free in Dawn in Google Chrome prior to 146.0.7680.178 allowed a remote attacker who had compromised the renderKEVEXPLOITEDPATCHED
chrome· CVSS 8.8· CWE-416
119🔥
14 art.
0
Apr 1, 2026
9.8
wp ninjas · CVE-2026-0740 — Ninja Forms - File Upload <= 3.3.26 - Unauthenticated Arbitrary File UploadKEVEXPLOITED
ninja forms - file uploads· CVSS 9.8· CWE-434
112🔥
3 art.
0
Apr 7, 2026
9.8
ivanti · CVE-2026-1281 — A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution.KEVEXPLOITEDPATCHED
endpoint_manager_mobile· CVSS 9.8· CWE-94
110🔥
2 art.
0
Jan 29, 2026
9.8
fortinet · CVE-2026-21643 — An improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiClientEMS 7.4.4 may allow an unauthenticated attacker to execute unauthorized codKEVEXPLOITEDPATCHED
forticlientems· CVSS 9.8· CWE-89
104🔥
10 art.
0
Feb 6, 2026
7.8
trueconf · CVE-2026-3502 — TrueConf Client Update Integrity Verification BypassKEVEXPLOITED
trueconf· CVSS 7.8· CWE-494
92
7 art.
1
Mar 30, 2026
9.8
weaver · CVE-2026-22679 — Weaver E-cology 10.0 Unauthenticated RCE via dubboApi Debug EndpointKEVEXPLOITEDPATCHED
e-cology· CVSS 9.8· CWE-306
86
1 art.
0
Apr 7, 2026
7.8
microsoft · CVE-2026-21509 — Reliance on untrusted inputs in a security decision in Microsoft Office allows an unauthorized attacker to bypass a security feature locally.KEVEXPLOITED
365_apps· CVSS 7.8· CWE-807
85
1 art.
0
Jan 26, 2026
8.8
microsoft · CVE-2026-21513 — Protection mechanism failure in MSHTML Framework allows an unauthorized attacker to bypass a security feature over a network.KEVEXPLOITEDPATCHED
windows_10_1607· CVSS 8.8· CWE-693
85
1 art.
0
Feb 10, 2026
→ View full list

Pre-CVE Events

View all
What’s New in Rapid7 Products and Services: Q1 2026 in Review
1 sources
Security Bypass Vulnerability in LangChain
MEDIUM1 sources
Information Disclosure Vulnerability in Proxmox Virtual Environment
proxmox server solutionsMEDIUM1 sources
Multiple Vulnerabilities in SugarCRM Sugar Enterprise Allow Privilege Escalation, XSS, Security Bypass, Data Manipulation, Information Disclosure, and DoS
sugarcrmHIGH1 sources
New Lua-based malware 'LucidRook' observed in targeted attacks against Taiwanese organizations
1 sources

Latest news

View all
[B]microsoft
Security Alert: Microsoft Releases March 2026 Security Updates
[B]microsoftCVE-2026-20805
Security Alert: Microsoft Releases January 2026 Security Updates
[B]adobeCVE-2026-27220
Security Alert: Alert Regarding Vulnerabilities in Adobe Acrobat and Reader (APSB26-26)
[B]microsoftCVE-2026-21510
Security Alert: Microsoft Releases February 2026 Security Updates
[B]adobe
Security Alert: Alert Regarding Vulnerabilities in Adobe Acrobat and Reader (APSB25-119)
[B]microsoftCVE-2025-62221
Security Alert: Microsoft Releases December 2025 Security Updates
[C]
What’s New in Rapid7 Products and Services: Q1 2026 in Review
58m ago
[C]mattermostCVE-2026-24661
CVE-2026-24661 | Mattermost Plugins up to 2.1.3 Changes Webhook Endpoint allocation of resources
1h ago