Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
2836 articles · 111043 vulns · 38/41 feeds (7d)
706
+102 today
Exploited (7d)
148
+48 today
Critical (7d)
1543
CISA KEV
22
Pre-CVE
2836
+541 today
Articles (7d)

Threat Briefing

Global

Loading...

About Zero Day Monitor

Open-source vulnerability intelligence for security teams. The platform scans 41 security feeds, analyzes articles with AI, and surfaces the threats that matter. Track trending CVEs, discover zero-days before they get a CVE ID, and monitor your vendor stack for supply-chain risks.

Trending
Ranked by source count
Zero-Days
Pre-CVE detection
Verification
Community-driven
Open Source
AGPL-3.0 licensed
Learn more about the projectSign in for personalized features

Vulnerabilities

6.5
microsoft · CVE-2026-32201 — Microsoft SharePoint Server Spoofing VulnerabilityKEVEXPLOITEDPATCHED
sharepoint_server· CVSS 6.5· CWE-20
151🔥
13 art.
0
Apr 14, 2026
9.1
fortinet · CVE-2026-21643 — CVE-2026-21643: An improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiCKEVEXPLOITED
PATCHED
forticlientems· CVSS 9.1· CWE-89
136🔥
13 art.
0
Feb 6, 2026
8.6
adobe · CVE-2026-34621 — Acrobat Reader | Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') (CWE-1321)KEVEXPLOITEDPATCHED
acrobat_dc· CVSS 8.6· CWE-1321
133🔥
15 art.
0
Apr 11, 2026
9.8
nginxui · CVE-2026-33032 — Nginx UI is a web user interface for the Nginx web server. In versions 2.3.5 and prior, the nginx-ui MCP (Model Context Protocol) integration exposes two HTTP endpoints: /mcp and /mcp_message. While /KEVEXPLOITED
nginx_ui· CVSS 9.8· CWE-306
117🔥
4 art.
0
Mar 30, 2026
9.8
fortinet · CVE-2026-35616 — CVE-2026-35616: A improper access control vulnerability in Fortinet FortiClientEMS 7.4.5 through 7.4.6 may allow an unauthenticated attaKEVEXPLOITEDPATCHED
forticlientems· CVSS 9.8· CWE-284
114🔥
18 art.
0
Apr 4, 2026
9.8
nginxui · CVE-2026-27944 — Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.3, the /api/backup endpoint is accessible without authentication and discloses the encryption keys required to decrypt tKEVEXPLOITEDPATCHED
nginx_ui· CVSS 9.8· CWE-306
98
1 art.
0
Mar 5, 2026
9.3
marimo · CVE-2026-39987 — marimo Affected by Pre-Auth Remote Code Execution via Terminal WebSocket Authentication BypassKEVEXPLOITEDPATCHED
marimo· CVSS 9.3· CWE-306
98
6 art.
0
Apr 8, 2026
8.8
microsoft · CVE-2026-21262 — SQL Server Elevation of Privilege VulnerabilityKEVEXPLOITEDPATCHED
sql_server_2016· CVSS 8.8· CWE-284
92
1 art.
0
Mar 10, 2026
9.8
microsoft · CVE-2026-33824 — Windows Internet Key Exchange (IKE) Service Extensions Remote Code Execution VulnerabilityEXPLOITEDPATCHED
windows ike extension· CVSS 9.8· CWE-415
90
7 art.
0
Apr 14, 2026
10.0
axios · CVE-2026-40175 — Axios has Unrestricted Cloud Metadata Exfiltration via Header Injection ChainEXPLOITEDPATCHED
axios· CVSS 10.0· CWE-113
87
4 art.
0
Apr 10, 2026
→ View full list

Pre-CVE Events

View all
ZERO-DAYMalicious Code Injection via Axios npm Package Maintainer Account Takeover
axiosMEDIUM1 sourcesverified
ZERO-DAYADV990001 Latest Servicing Stack Updates
1 sourcesverified
Qualys VMDR and TotalCloud™ Now Available on Oracle Cloud Marketplace
1 sources
Multiple Vulnerabilities in AMD EPYC, Ryzen, and Embedded Processors
amd1 sources
Multiple vulnerabilities in Splunk products
splunk1 sources

Latest news

View all
[B]microsoftCVE-2026-21510
Security Alert: Microsoft Releases February 2026 Security Updates
[B]microsoftCVE-2026-20805
Security Alert: Microsoft Releases January 2026 Security Updates
[B]microsoftCVE-2026-32201
Security Alert: Microsoft Releases April 2026 Security Updates
[B]adobe
Security Alert: Alert Regarding Vulnerabilities in Adobe Acrobat and Reader (APSB26-44)
[B]microsoft
Security Alert: Microsoft Releases March 2026 Security Updates
[B]adobe
Security Alert: Alert Regarding Vulnerabilities in Adobe Acrobat and Reader (APSB25-119)
[B]microsoftCVE-2025-62221
Security Alert: Microsoft Releases December 2025 Security Updates
[B]adobeCVE-2026-27220
Security Alert: Alert Regarding Vulnerabilities in Adobe Acrobat and Reader (APSB26-26)