Zero Day Monitor
Dashboard
Vulnerabilities
Trending
Zero-Days
News
Login
105734
New CVEs
253
Critical
0
Pre-CVE
1386
CISA KEV
1777
Articles
36/41
Feeds
Vulnerabilities
Trending
Newest
Urgent
8.8
aquasec ·
CVE-2026-33634 —
Trivy ecosystem supply chain briefly compromised
KEV
EXPLOITED
setup-trivy
· CVSS 8.8
· CWE-506
123
🔥
2 articles
0
Mar 23, 2026
9.3
langflow ·
CVE-2026-33017 —
Langflow is a tool for building and deploying AI-powered agents and workflows. In versions prior to 1.9.0, the POST /api/v1/build_public_tmp/{flow_id}/flow endpoint allows building public flows withou
KEV
EXPLOITED
langflow
· CVSS 9.3
· CWE-94
115
🔥
7 articles
0
Mar 20, 2026
9.3
Cloud Software Group ·
CVE-2026-3055 —
Insufficient input validation in NetScaler ADC and NetScaler Gateway when configured as a SAML IDP leading to memory overread
KEV
EXPLOITED
NetScaler ADC and NetScaler Gateway
· CVSS 9.3
· CWE-125
104
🔥
7 articles
0
Mar 23, 2026
0.0
linux ·
CVE-2026-23400 —
rust_binder: call set_notification_done() without proc lock
EXPLOITED
linux kernel
· CVSS 0.0
83
15 articles
0
Mar 29, 2026
9.8
gnu ·
CVE-2026-24061 —
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment variable.
KEV
EXPLOITED
inetutils
· CVSS 9.8
· CWE-88
68
1 articles
0
Jan 21, 2026
8.8
microsoft ·
CVE-2026-21510 —
Protection mechanism failure in Windows Shell allows an unauthorized attacker to bypass a security feature over a network.
KEV
EXPLOITED
windows_10_1607
· CVSS 8.8
· CWE-693
65
1 articles
0
Feb 10, 2026
7.5
micromatch ·
CVE-2026-33671 —
Picomatch has a ReDoS vulnerability via extglob quantifiers
EXPLOITED
picomatch
· CVSS 7.5
· CWE-1333
64
2 articles
0
Mar 26, 2026
5.5
microsoft ·
CVE-2026-20805 —
Exposure of sensitive information to an unauthorized actor in Desktop Windows Manager allows an authorized attacker to disclose information locally.
KEV
EXPLOITED
windows_10_1607
· CVSS 5.5
· CWE-200
63
1 articles
0
Jan 13, 2026
7.5
isc ·
CVE-2026-3591 —
A use-after-return vulnerability exists in the `named` server when handling DNS queries signed with SIG(0). Using a specially-crafted DNS request, an attacker may be able to cause an ACL to improperly
EXPLOITED
BIND 9
· CVSS 7.5
· CWE-305
62
4 articles
0
Mar 25, 2026
10.0
oracle ·
CVE-2026-21962 —
Vulnerability in the Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in product of Oracle Fusion Middleware (component: Weblogic Server Proxy Plug-in for Apache HTTP Server, Weblogic Server Prox
KEV
EXPLOITED
http_server
· CVSS 10.0
· CWE-284
62
1 articles
0
Jan 20, 2026
→ View full list
Urgent
27.4
aquasec setup-trivy
CVE-2026-33634
KEV
5d ago
25.5
linux linux kernel
CVE-2026-23400
EXP
today
25.4
Cloud Software Group NetScaler ADC and NetScaler Gateway
CVE-2026-3055
KEV
5d ago
22.0
linux linux kernel
CVE-2026-23399
EXP
1d ago
21.6
langflow langflow
CVE-2026-33017
KEV
9d ago
21.4
wazuh wazuh-manager
CVE-2025-15615
EXP
2d ago
20.7
n/a n/a
CVE-2026-30532
EXP
2d ago
20.7
n/a n/a
CVE-2026-30533
EXP
2d ago
20.7
n/a n/a
CVE-2026-30303
EXP
2d ago
20.7
n/a n/a
CVE-2026-30302
EXP
2d ago
View full list
Latest news
[JPCERT/CC]
Security Alert: Microsoft Releases February 2026 Security Up...
[JPCERT/CC]
Security Alert: Microsoft Releases March 2026 Security Updat...
[JPCERT/CC]
Security Alert: Alert Regarding Vulnerabilities in Adobe Acr...
[JPCERT/CC]
Security Alert: Microsoft Releases January 2026 Security Upd...
[JPCERT/CC]
Security Alert: Alert Regarding Vulnerabilities in Adobe Acr...
[JPCERT/CC]
Security Alert: Microsoft Releases December 2025 Security Up...
[VulDB]
CVE-2026-34005 | Xiongmai AHB7008T-MH-V2 /NBD7024H-P 4.03.R1...
3h ago
[VulDB]
CVE-2026-33574 | OpenClaw up to 2026.3.7 toctou (GHSA-vhwf-4...
4h ago
Pipeline
0
Queued
0
Analyzing
154
Today