Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNews
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
2837 articles · 106441 vulns · 38/41 feeds (7d)
437
+99 today
Exploited (7d)
238
+67 today
Critical (7d)
1388
CISA KEV
6
Pre-CVE
2837
+552 today
Articles (7d)

Vulnerabilities

9.3
Cloud Software Group · CVE-2026-3055 — Insufficient input validation leading to memory overreadKEVEXPLOITEDPATCHED
NetScaler ADC and NetScaler Gateway· CVSS 9.3· CWE-125
143🔥
18 art.
0
Mar 23, 2026
9.1
fortinet · CVE-2026-21643 — CVE-2026-21643: An improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiCKEVEXPLOITEDPATCHED
forticlientems· CVSS 9.1· CWE-89
137🔥
8 art.
0
Feb 6, 2026
8.8
aquasec · CVE-2026-33634 — Trivy ecosystem supply chain briefly compromisedKEVEXPLOITEDPATCHED
setup-trivy· CVSS 8.8· CWE-506
103🔥
3 art.
0
Mar 23, 2026
7.8
trueconf · CVE-2026-3502 — TrueConf Client Update Integrity Verification BypassKEVEXPLOITED
trueconf client· CVSS 7.8· CWE-494
102🔥
2 art.
0
Mar 30, 2026
—
google · CVE-2026-5281 — CVE-2026-5281: Use after free in Dawn in Google Chrome prior to 146.0.7680.178 allowed a remote attacker who had compromised the renderKEVEXPLOITEDPATCHED
chrome· CWE-416
98
1 art.
0
Apr 1, 2026
8.8
google · CVE-2026-3910 — Inappropriate implementation in V8 in Google Chrome prior to 146.0.7680.75 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: HiKEVEXPLOITEDPATCHED
chrome· CVSS 8.8· CWE-94
97
1 art.
0
Mar 13, 2026
8.8
google · CVE-2026-3909 — Out of bounds write in Skia in Google Chrome prior to 146.0.7680.75 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)KEVEXPLOITEDPATCHED
chrome· CVSS 8.8· CWE-787
97
1 art.
0
Mar 13, 2026
10.0
oracle · CVE-2026-21962 — Vulnerability in the Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in product of Oracle Fusion Middleware (component: Weblogic Server Proxy Plug-in for Apache HTTP Server, Weblogic Server ProxKEVEXPLOITEDPATCHED
http_server· CVSS 10.0· CWE-284
86
2 art.
0
Jan 20, 2026
9.3
langflow · CVE-2026-33017 — Langflow is a tool for building and deploying AI-powered agents and workflows. In versions prior to 1.9.0, the POST /api/v1/build_public_tmp/{flow_id}/flow endpoint allows building public flows withouKEVEXPLOITEDPATCHED
langflow· CVSS 9.3· CWE-94
80
9 art.
0
Mar 20, 2026
9.8
go · CVE-2026-33032 — Nginx UI: Unauthenticated MCP Endpoint Allows Remote Nginx TakeoverEXPLOITED
github.com/0xjacky/nginx-ui· CVSS 9.8· CWE-306
74
2 art.
0
Mar 30, 2026
→ View full list

Pre-CVE Events

View all
ZERO-DAYKVM shadow EPT stale rmap use-after-free
red hatHIGH1 sourcesverified
Multiple Vulnerabilities in Joomla CMS Allow Security Bypass, SQL Injection, and Cross-Site Scripting
joomlaHIGH1 sources
A Taxonomy of Cognitive Security
1 sources
Multiple Vulnerabilities in Google Chrome and Microsoft Edge
HIGH1 sources
Multiple Vulnerabilities in cPanel/WHM Allow Security Bypass, XSS, SSRF, Information Disclosure, and Potential Code Execution
cpanel, l.l.c.HIGH1 sources

Latest news

View all
[B]microsoftCVE-2026-20805
Security Alert: Microsoft Releases January 2026 Security Updates
[B]microsoftCVE-2025-62221
Security Alert: Microsoft Releases December 2025 Security Updates
[B]adobe
Security Alert: Alert Regarding Vulnerabilities in Adobe Acrobat and Reader (APSB26-26)
[B]microsoftCVE-2026-21510
Security Alert: Microsoft Releases February 2026 Security Updates
[B]microsoft
Security Alert: Microsoft Releases March 2026 Security Updates
[B]adobe
Security Alert: Alert Regarding Vulnerabilities in Adobe Acrobat and Reader (APSB25-119)
[B]zscalerCVE-2026-22569
[NEU] [mittel] ZScaler Client Connector: Schwachstelle ermöglicht Manipulation von Daten
4m ago
[B]
[NEU] [hoch] Google Chrome: Mehrere Schwachstellen
4m ago