Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
2724 articles · 110521 vulns · 36/41 feeds (7d)
682
+69 today
Exploited (7d)
157
+29 today
Critical (7d)
1542
CISA KEV
8
Pre-CVE
2724
+332 today
Articles (7d)

Threat Briefing

Global

Loading...

About Zero Day Monitor

Open-source vulnerability intelligence for security teams. The platform scans 41 security feeds, analyzes articles with AI, and surfaces the threats that matter. Track trending CVEs, discover zero-days before they get a CVE ID, and monitor your vendor stack for supply-chain risks.

Trending
Ranked by source count
Zero-Days
Pre-CVE detection
Verification
Community-driven
Open Source
AGPL-3.0 licensed
Learn more about the projectSign in for personalized features

Vulnerabilities

9.1
fortinet · CVE-2026-21643 — CVE-2026-21643: An improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiCKEVEXPLOITEDPATCHED
forticlientems· CVSS 9.1· CWE-89
160🔥
13 art.
0
Feb 6, 2026
8.6
adobe · CVE-2026-34621 — Acrobat Reader | Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') (CWE-1321)KEV
EXPLOITED
PATCHED
acrobat_dc· CVSS 8.6· CWE-1321
153🔥
13 art.
0
Apr 11, 2026
9.8
fortinet · CVE-2026-35616 — CVE-2026-35616: A improper access control vulnerability in Fortinet FortiClientEMS 7.4.5 through 7.4.6 may allow an unauthenticated attaKEVEXPLOITEDPATCHED
forticlientems· CVSS 9.8· CWE-284
138🔥
18 art.
0
Apr 4, 2026
9.3
marimo · CVE-2026-39987 — marimo Affected by Pre-Auth Remote Code Execution via Terminal WebSocket Authentication BypassKEVEXPLOITEDPATCHED
marimo· CVSS 9.3· CWE-306
119🔥
6 art.
0
Apr 8, 2026
9.8
gnu · CVE-2026-24061 — telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment variable.KEVEXPLOITEDPATCHED
inetutils· CVSS 9.8· CWE-88
85
1 art.
0
Jan 21, 2026
8.8
openclaw · CVE-2026-25253 — OpenClaw (aka clawdbot or Moltbot) before 2026.1.29 obtains a gatewayUrl value from a query string and automatically makes a WebSocket connection without prompting, sending a token value.KEVEXPLOITEDPATCHED
openclaw· CVSS 8.8· CWE-669
85
1 art.
0
Feb 1, 2026
8.8
google · CVE-2026-5281 — CVE-2026-5281: Use after free in Dawn in Google Chrome prior to 146.0.7680.178 allowed a remote attacker who had compromised the renderKEVEXPLOITEDPATCHED
chrome· CVSS 8.8· CWE-416
83
15 art.
0
Apr 1, 2026
9.3
wolfssl · CVE-2026-5194 — wolfSSL ECDSA Certificate VerificationEXPLOITEDPATCHED
wolfssl· CVSS 9.3· CWE-295
74
5 art.
0
Apr 9, 2026
9.8
ivanti · CVE-2026-1340 — CVE-2026-1340: A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution.KEVEXPLOITEDPATCHED
endpoint_manager_mobile· CVSS 9.8· CWE-94
70
3 art.
0
Jan 29, 2026
7.5
ffmpeg · CVE-2026-30997 — CVE-2026-30997: An out-of-bounds read in the read_global_param() function (libavcodec/av1dec.c) of FFmpeg v8.0.1 allows attackers to cauEXPLOITED
ffmpeg· CVSS 7.5· CWE-125
67
2 art.
0
Apr 13, 2026
→ View full list

Pre-CVE Events

View all
Multiple vulnerabilities in Samsung mobile devices prior to SMR-APR-2026 Release 1
samsung1 sources
State-sponsored threats: Different objectives, similar access paths
1 sources
Multiple Vulnerabilities in BigBlueButton Allow Data Manipulation and User Redirection
MEDIUM1 sources
How Hackers Are Thinking About AI
1 sources
Multiple Vulnerabilities in Apache Airflow Allow Arbitrary Code Execution and Security Bypass
apacheHIGH1 sources

Latest news

View all
[B]adobeCVE-2026-27220
Security Alert: Alert Regarding Vulnerabilities in Adobe Acrobat and Reader (APSB26-26)
[B]microsoftCVE-2026-21510
Security Alert: Microsoft Releases February 2026 Security Updates
[B]adobe
Security Alert: Alert Regarding Vulnerabilities in Adobe Acrobat and Reader (APSB25-119)
[B]microsoftCVE-2025-62221
Security Alert: Microsoft Releases December 2025 Security Updates
[B]microsoftCVE-2026-20805
Security Alert: Microsoft Releases January 2026 Security Updates
[B]microsoft
Security Alert: Microsoft Releases March 2026 Security Updates
[B]sapCVE-2026-24318
SAP security advisory – April 2026 monthly rollup (AV26-349)
50m ago
[C]n/aCVE-2026-31049
CVE-2026-31049 | Hostbill 2025-11-24/2025-12-01 Registration csv injection
57m ago