Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
2856 articles · 109428 vulns · 38/41 feeds (7d)
660
+76 today
Exploited (7d)
355
+71 today
Critical (7d)
1533
CISA KEV
26
Pre-CVE
2856
+557 today
Articles (7d)

Threat Briefing

Global

Loading...

About Zero Day Monitor

Open-source vulnerability intelligence for security teams. The platform scans 41 security feeds, analyzes articles with AI, and surfaces the threats that matter. Track trending CVEs, discover zero-days before they get a CVE ID, and monitor your vendor stack for supply-chain risks.

Trending
Ranked by source count
Zero-Days
Pre-CVE detection
Verification
Community-driven
Open Source
AGPL-3.0 licensed
Learn more about the projectSign in for personalized features

Vulnerabilities

9.8
ivanti · CVE-2026-1340 — CVE-2026-1340: A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution.KEVEXPLOITEDPATCHED
endpoint_manager_mobile· CVSS 9.8· CWE-94
143🔥
3 art.
0
Jan 29, 2026
9.1
fortinet · CVE-2026-35616 — CVE-2026-35616: A improper access control vulnerability in Fortinet FortiClientEMS 7.4.5 through 7.4.6 may allow an unauthenticated attaKEV
EXPLOITED
PATCHED
forticlientems· CVSS 9.1· CWE-284
133🔥
17 art.
0
Apr 4, 2026
8.8
google · CVE-2026-5281 — CVE-2026-5281: Use after free in Dawn in Google Chrome prior to 146.0.7680.178 allowed a remote attacker who had compromised the renderKEVEXPLOITEDPATCHED
chrome· CVSS 8.8· CWE-416
118🔥
14 art.
0
Apr 1, 2026
9.8
wp ninjas · CVE-2026-0740 — Ninja Forms - File Upload <= 3.3.26 - Unauthenticated Arbitrary File UploadKEVEXPLOITED
ninja forms - file uploads· CVSS 9.8· CWE-434
112🔥
3 art.
0
Apr 7, 2026
9.8
ivanti · CVE-2026-1281 — A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution.KEVEXPLOITEDPATCHED
endpoint_manager_mobile· CVSS 9.8· CWE-94
110🔥
2 art.
0
Jan 29, 2026
9.8
fortinet · CVE-2026-21643 — An improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiClientEMS 7.4.4 may allow an unauthenticated attacker to execute unauthorized codKEVEXPLOITEDPATCHED
forticlientems· CVSS 9.8· CWE-89
103🔥
10 art.
0
Feb 6, 2026
7.8
trueconf · CVE-2026-3502 — TrueConf Client Update Integrity Verification BypassKEVEXPLOITED
trueconf· CVSS 7.8· CWE-494
91
7 art.
1
Mar 30, 2026
8.8
apache · CVE-2026-34197 — Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Authenticated users could perform RCE via Jolokia MBeansEXPLOITEDPATCHED
apache activemq· CVSS 8.8· CWE-20
85
8 art.
0
Apr 7, 2026
7.8
microsoft · CVE-2026-21509 — Reliance on untrusted inputs in a security decision in Microsoft Office allows an unauthorized attacker to bypass a security feature locally.KEVEXPLOITED
365_apps· CVSS 7.8· CWE-807
84
1 art.
0
Jan 26, 2026
8.8
microsoft · CVE-2026-21513 — Protection mechanism failure in MSHTML Framework allows an unauthorized attacker to bypass a security feature over a network.KEVEXPLOITEDPATCHED
windows_10_1607· CVSS 8.8· CWE-693
84
1 art.
0
Feb 10, 2026
→ View full list

Pre-CVE Events

View all
What’s New in Rapid7 Products and Services: Q1 2026 in Review
1 sources
Security Bypass Vulnerability in LangChain
MEDIUM1 sources
Information Disclosure Vulnerability in Proxmox Virtual Environment
proxmox server solutionsMEDIUM1 sources
Multiple Vulnerabilities in SugarCRM Sugar Enterprise Allow Privilege Escalation, XSS, Security Bypass, Data Manipulation, Information Disclosure, and DoS
sugarcrmHIGH1 sources
New Lua-based malware 'LucidRook' observed in targeted attacks against Taiwanese organizations
1 sources

Latest news

View all
[B]adobeCVE-2026-27220
Security Alert: Alert Regarding Vulnerabilities in Adobe Acrobat and Reader (APSB26-26)
[B]adobe
Security Alert: Alert Regarding Vulnerabilities in Adobe Acrobat and Reader (APSB25-119)
[B]microsoftCVE-2025-62221
Security Alert: Microsoft Releases December 2025 Security Updates
[B]microsoftCVE-2026-20805
Security Alert: Microsoft Releases January 2026 Security Updates
[B]microsoftCVE-2026-21510
Security Alert: Microsoft Releases February 2026 Security Updates
[B]microsoft
Security Alert: Microsoft Releases March 2026 Security Updates
[C]fernandobtCVE-2026-3005
CVE-2026-3005 | fernandobt List Category Posts Plugin up to 0.94.0 on WordPress Shortcode catlist cross site scripting
1h ago
[C]ladelaCVE-2026-2519
CVE-2026-2519 | ladela Bookly Plugin up to 27.0 on WordPress Negative Number tips external control of assumed-immutable web parameter
1h ago