Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
2613 articles · 156754 vulns · 36/41 feeds (7d)
483
+175 today
Exploited (7d)
238
+143 today
Critical (7d)
1628
CISA KEV
122
Pre-CVE
2613
+1131 today
Articles (7d)

Threat Briefing

Global

Loading...

About Zero Day Monitor

Open-source vulnerability intelligence for security teams. The platform scans 41 security feeds, analyzes articles with AI, and surfaces the threats that matter. Track trending CVEs, discover zero-days before they get a CVE ID, and monitor your vendor stack for supply-chain risks.

Trending
Ranked by source count
Zero-Days
Pre-CVE detection
Verification
Community-driven
Open Source
AGPL-3.0 licensed
Learn more about the projectSign in for personalized features

Vulnerabilities

9.8
drupal · CVE-2026-9082 — Drupal core - Highly critical - SQL injection - SA-CORE-2026-004KEVEXPLOITEDPATCHED
drupal core· CVSS 9.8· CWE-89
138🔥
14 art.
0
May 20, 2026
7.8
microsoft · CVE-2026-41091 — Microsoft Defender Elevation of Privilege VulnerabilityKEVEXPLOITED
PATCHED
malware_protection_engine· CVSS 7.8· CWE-59
134🔥
13 art.
0
May 20, 2026
7.8
linux · CVE-2026-31431 — crypto: algif_aead - Revert to operating out-of-placeKEVEXPLOITEDPATCHED
linux_kernel· CVSS 7.8
134🔥
82 art.
0
Apr 22, 2026
10.0
litespeedtech · CVE-2026-48172 — CVE-2026-48172: LiteSpeed User-End cPanel Plugin before 2.4.5 allows privilege escalation (possibly to root), as exploited in the wild iKEVEXPLOITEDPATCHED
litespeed_cpanel_plugin· CVSS 10.0· CWE-266
130🔥
4 art.
0
May 21, 2026
9.8
cpanel · CVE-2026-41940 — WebPros cPanel and WHM Authentication Bypass via Login FlowKEVEXPLOITEDPATCHED
cpanel· CVSS 9.8· CWE-306
129🔥
23 art.
0
Apr 29, 2026
8.8
linux · CVE-2026-43284 — xfrm: esp: avoid in-place decrypt on shared skb fragsKEVEXPLOITEDPATCHED
linux_kernel· CVSS 8.8
128🔥
30 art.
0
May 8, 2026
7.8
linux · CVE-2026-43500 — rxrpc: Also unshare DATA/RESPONSE packets when paged frags are presentKEVEXPLOITEDPATCHED
linux_kernel· CVSS 7.8· CWE-20
123🔥
14 art.
0
May 11, 2026
9.1
digital knowledge · CVE-2026-5426 — KnowledgeDeliver deployments before February 24, 2026 use a static ASP.NET/IIS machineKey valueKEVEXPLOITEDPATCHED
knowledgedeliver· CVSS 9.1· CWE-321
121🔥
5 art.
0
Apr 16, 2026
4.0
microsoft · CVE-2026-45498 — Microsoft Defender Denial of Service VulnerabilityKEVEXPLOITEDPATCHED
defender_antimalware_platform· CVSS 4.0· CWE-400
117🔥
7 art.
0
May 20, 2026
8.1
f5 · CVE-2026-42945 — NGINX ngx_http_rewrite_module vulnerabilityKEVEXPLOITEDPATCHED
nginx· CVSS 8.1· CWE-122
115🔥
22 art.
0
May 13, 2026
→ View full list

Pre-CVE Events

View all
ZERO-DAYMalicious Code Injection via Axios npm Package Maintainer Account Takeover
axiosMEDIUM1 sourcesverified
ZERO-DAYADV990001 Latest Servicing Stack Updates
1 sourcesverified
Multiple Firmware Security Vulnerabilities in Phoenix Contact PLCnext Products
phoenix contact1 sources
Multiple Vulnerabilities in Symfony Framework
symfony sas1 sources
Multiple vulnerabilities in Check Point products
check point software technologies1 sources

Latest news

View all
[B]adobe
Security Alert: Alert Regarding Vulnerabilities in Adobe Acrobat and Reader (APSB26-44)
[B]microsoftCVE-2025-62221
Security Alert: Microsoft Releases December 2025 Security Updates
[B]microsoft
Security Alert: Microsoft Releases May 2026 Security Updates
[B]adobeCVE-2026-27220
Security Alert: Alert Regarding Vulnerabilities in Adobe Acrobat and Reader (APSB26-26)
[B]microsoftCVE-2026-20805
Security Alert: Microsoft Releases January 2026 Security Updates
[B]microsoftCVE-2026-21510
Security Alert: Microsoft Releases February 2026 Security Updates
[B]microsoftCVE-2026-32201
Security Alert: Microsoft Releases April 2026 Security Updates
[B]microsoft
Security Alert: Microsoft Releases March 2026 Security Updates