Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
2409 articles · 160665 vulns · 36/41 feeds (7d)
615
+36 today
Exploited (7d)
304
+22 today
Critical (7d)
1643
CISA KEV
185
Pre-CVE
2409
+152 today
Articles (7d)

Threat Briefing

Global

Loading...

About Zero Day Monitor

Open-source vulnerability intelligence for security teams. The platform scans 41 security feeds, analyzes articles with AI, and surfaces the threats that matter. Track trending CVEs, discover zero-days before they get a CVE ID, and monitor your vendor stack for supply-chain risks.

Trending
Ranked by source count
Zero-Days
Pre-CVE detection
Verification
Community-driven
Open Source
AGPL-3.0 licensed
Learn more about the projectSign in for personalized features

Vulnerabilities

10.0
cis · CVE-2026-20182 — Cisco Catalyst SD-WAN Controller Authentication Bypass VulnerabilityKEVEXPLOITEDPATCHED
catalyst_sd-wan_manager· CVSS 10.0· CWE-287
155🔥
23 art.
0
May 14, 2026
8.8
apache · CVE-2026-34197 — Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Authenticated users could perform RCE via Jolokia MBeansKEVEXPLOITED
PATCHED
activemq· CVSS 8.8· CWE-20
137🔥
20 art.
0
Apr 7, 2026
7.5
solarwinds · CVE-2026-28318 — SolarWinds Serv-U Unauthenticated Denial of Service VulnerabilityKEVEXPLOITED
serv-u· CVSS 7.5· CWE-400
133🔥
4 art.
0
Jun 4, 2026
9.8
everest forms · CVE-2026-3300 — The Everest Forms Pro plugin for WordPress is vulnerable to Remote Code Execution via PHP Code Injection in all versions up to, and including, 1.9.12. This is due to the Calculation Addon's process_fiKEVEXPLOITED
everest forms pro· CVSS 9.8· CWE-94
114🔥
4 art.
0
Mar 31, 2026
7.9
linux · CVE-2026-43500 — rxrpc: Also unshare DATA/RESPONSE packets when paged frags are presentKEVEXPLOITEDPATCHED
linux_kernel· CVSS 7.9· CWE-20
113🔥
22 art.
0
May 11, 2026
7.8
microsoft · CVE-2026-41091 — Microsoft Defender Elevation of Privilege VulnerabilityKEVEXPLOITEDPATCHED
malware_protection_engine· CVSS 7.8· CWE-59
97
18 art.
0
May 20, 2026
7.8
microsoft · CVE-2026-33825 — Microsoft Defender Elevation of Privilege VulnerabilityKEVEXPLOITEDPATCHED
defender_antimalware_platform· CVSS 7.8· CWE-1220
97
23 art.
0
Apr 14, 2026
9.8
mirasvit · CVE-2026-45247 — Mirasvit Cache Warmer for Magento < 1.11.12 PHP Object InjectionKEVEXPLOITEDPATCHED
full_page_cache_warmer· CVSS 9.8· CWE-502
96
3 art.
0
May 26, 2026
7.9
linux · CVE-2026-43284 — xfrm: esp: avoid in-place decrypt on shared skb fragsKEVEXPLOITEDPATCHED
linux_kernel· CVSS 7.9· CWE-20
93
37 art.
0
May 8, 2026
7.8
palo alto networks · CVE-2026-0257 — PAN-OS: GlobalProtect Authentication Bypass VulnerabilitiesEXPLOITEDPATCHED
pan-os· CVSS 7.8· CWE-565
92
14 art.
0
May 13, 2026
→ View full list

Pre-CVE Events

View all
ZERO-DAYMalicious Code Injection via Axios npm Package Maintainer Account Takeover
axiosMEDIUM1 sourcesverified
ZERO-DAYADV990001 Latest Servicing Stack Updates
1 sourcesverified
FreeType Heap Buffer Overflow via Improper Limit Calculation in TrueType SHZ Instruction
freetype-project.org1 sources
3 Principles to Safely Scale Agentic AI
1 sources
Seeking Counsel: Ongoing Targeted Campaign Against US Law Firms
1 sources

Latest news

View all
[B]adobeCVE-2026-27220
Security Alert: Alert Regarding Vulnerabilities in Adobe Acrobat and Reader (APSB26-26)
[B]microsoftCVE-2025-62221
Security Alert: Microsoft Releases December 2025 Security Updates
[B]trend microCVE-2026-34926
Security Alert: Alert Regarding Multiple Vulnerabilities in Trend Micro Products Including TrendAI Apex One
[B]microsoft
Security Alert: Microsoft Releases March 2026 Security Updates
[B]adobe
Security Alert: Alert Regarding Vulnerabilities in Adobe Acrobat and Reader (APSB25-119)
[B]microsoftCVE-2026-20805
Security Alert: Microsoft Releases January 2026 Security Updates
[B]microsoftCVE-2026-21510
Security Alert: Microsoft Releases February 2026 Security Updates
[B]microsoftCVE-2026-32201
Security Alert: Microsoft Releases April 2026 Security Updates