Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
1892 articles · 155795 vulns · 36/41 feeds (7d)
368
+78 today
Exploited (7d)
144
+33 today
Critical (7d)
1628
CISA KEV
119
Pre-CVE
1892
+338 today
Articles (7d)

Threat Briefing

Global

Loading...

About Zero Day Monitor

Open-source vulnerability intelligence for security teams. The platform scans 41 security feeds, analyzes articles with AI, and surfaces the threats that matter. Track trending CVEs, discover zero-days before they get a CVE ID, and monitor your vendor stack for supply-chain risks.

Trending
Ranked by source count
Zero-Days
Pre-CVE detection
Verification
Community-driven
Open Source
AGPL-3.0 licensed
Learn more about the projectSign in for personalized features

Vulnerabilities

9.8
drupal · CVE-2026-9082 — Drupal core - Highly critical - SQL injection - SA-CORE-2026-004KEVEXPLOITEDPATCHED
drupal· CVSS 9.8· CWE-89
159🔥
14 art.
0
May 20, 2026
7.8
microsoft · CVE-2026-41091 — Microsoft Defender Elevation of Privilege VulnerabilityKEVEXPLOITED
PATCHED
malware_protection_engine· CVSS 7.8· CWE-59
154🔥
13 art.
0
May 20, 2026
7.8
linux · CVE-2026-31431 — crypto: algif_aead - Revert to operating out-of-placeKEVEXPLOITEDPATCHED
linux_kernel· CVSS 7.8
154🔥
82 art.
0
Apr 22, 2026
9.8
cpanel · CVE-2026-41940 — WebPros cPanel and WHM Authentication Bypass via Login FlowKEVEXPLOITEDPATCHED
cpanel· CVSS 9.8· CWE-306
148🔥
23 art.
0
Apr 29, 2026
8.8
linux · CVE-2026-43284 — xfrm: esp: avoid in-place decrypt on shared skb fragsKEVEXPLOITEDPATCHED
linux_kernel· CVSS 8.8· CWE-20
147🔥
30 art.
0
May 8, 2026
7.8
linux · CVE-2026-43500 — rxrpc: Also unshare DATA/RESPONSE packets when paged frags are presentKEVEXPLOITEDPATCHED
linux_kernel· CVSS 7.8· CWE-20
142🔥
14 art.
0
May 11, 2026
4.0
microsoft · CVE-2026-45498 — Microsoft Defender Denial of Service VulnerabilityKEVEXPLOITEDPATCHED
defender_antimalware_platform· CVSS 4.0· CWE-400
134🔥
7 art.
0
May 20, 2026
8.1
f5 · CVE-2026-42945 — NGINX ngx_http_rewrite_module vulnerabilityKEVEXPLOITEDPATCHED
nginx· CVSS 8.1· CWE-122
132🔥
22 art.
0
May 13, 2026
6.7
trend micro · CVE-2026-34926 — CVE-2026-34926: A directory traversal vulnerability in the Apex One (on-premise) server could allow a pre-authenticated local attacker tKEVEXPLOITEDPATCHED
apex one· CVSS 6.7· CWE-23
123🔥
6 art.
0
May 21, 2026
7.5
digital knowledge · CVE-2026-5426 — KnowledgeDeliver deployments before February 24, 2026 use a static ASP.NET/IIS machineKey valueKEVEXPLOITEDPATCHED
knowledgedeliver· CVSS 7.5· CWE-321
121🔥
4 art.
0
Apr 16, 2026
→ View full list

Pre-CVE Events

View all
ZERO-DAYMalicious Code Injection via Axios npm Package Maintainer Account Takeover
axiosMEDIUM1 sourcesverified
ZERO-DAYADV990001 Latest Servicing Stack Updates
1 sourcesverified
Glassworm Botnet Takedown Targeting Software Developers
1 sources
CrowdStrike Recognized as Leader in Identity Threat Detection and Response
1 sources
D-Link DSL2600U 'rom-0' Admin Password Disclosure
d-link1 sources

Latest news

View all
[B]microsoftCVE-2025-62221
Security Alert: Microsoft Releases December 2025 Security Updates
[B]microsoft
Security Alert: Microsoft Releases May 2026 Security Updates
[B]microsoftCVE-2026-21510
Security Alert: Microsoft Releases February 2026 Security Updates
[B]adobeCVE-2026-27220
Security Alert: Alert Regarding Vulnerabilities in Adobe Acrobat and Reader (APSB26-26)
[B]microsoftCVE-2026-32201
Security Alert: Microsoft Releases April 2026 Security Updates
[B]adobe
Security Alert: Alert Regarding Vulnerabilities in Adobe Acrobat and Reader (APSB26-44)
[B]microsoft
Security Alert: Microsoft Releases March 2026 Security Updates
[B]adobe
Security Alert: Alert Regarding Vulnerabilities in Adobe Acrobat and Reader (APSB25-119)