Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
2813 articles · 111243 vulns · 38/41 feeds (7d)
663
+76 today
Exploited (7d)
179
+59 today
Critical (7d)
1543
CISA KEV
35
Pre-CVE
2813
+436 today
Articles (7d)

Threat Briefing

Global

Loading...

About Zero Day Monitor

Open-source vulnerability intelligence for security teams. The platform scans 41 security feeds, analyzes articles with AI, and surfaces the threats that matter. Track trending CVEs, discover zero-days before they get a CVE ID, and monitor your vendor stack for supply-chain risks.

Trending
Ranked by source count
Zero-Days
Pre-CVE detection
Verification
Community-driven
Open Source
AGPL-3.0 licensed
Learn more about the projectSign in for personalized features

Vulnerabilities

6.5
microsoft · CVE-2026-32201 — Microsoft SharePoint Server Spoofing VulnerabilityKEVEXPLOITEDPATCHED
sharepoint_server· CVSS 6.5· CWE-20
136🔥
13 art.
0
Apr 14, 2026
9.1
fortinet · CVE-2026-21643 — CVE-2026-21643: An improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiCKEVEXPLOITED
PATCHED
forticlientems· CVSS 9.1· CWE-89
120🔥
13 art.
0
Feb 6, 2026
8.6
adobe · CVE-2026-34621 — Acrobat Reader | Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') (CWE-1321)KEVEXPLOITEDPATCHED
acrobat_dc· CVSS 8.6· CWE-1321
117🔥
15 art.
0
Apr 11, 2026
9.8
nginxui · CVE-2026-33032 — Nginx UI is a web user interface for the Nginx web server. In versions 2.3.5 and prior, the nginx-ui MCP (Model Context Protocol) integration exposes two HTTP endpoints: /mcp and /mcp_message. While /KEVEXPLOITED
nginx_ui· CVSS 9.8· CWE-306
114🔥
5 art.
0
Mar 30, 2026
9.8
fortinet · CVE-2026-35616 — CVE-2026-35616: A improper access control vulnerability in Fortinet FortiClientEMS 7.4.5 through 7.4.6 may allow an unauthenticated attaKEVEXPLOITEDPATCHED
forticlientems· CVSS 9.8· CWE-284
104🔥
18 art.
0
Apr 4, 2026
9.3
marimo · CVE-2026-39987 — marimo Affected by Pre-Auth Remote Code Execution via Terminal WebSocket Authentication BypassKEVEXPLOITEDPATCHED
marimo· CVSS 9.3· CWE-306
89
6 art.
0
Apr 8, 2026
9.8
nginxui · CVE-2026-27944 — Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.3, the /api/backup endpoint is accessible without authentication and discloses the encryption keys required to decrypt tKEVEXPLOITEDPATCHED
nginx_ui· CVSS 9.8· CWE-306
89
1 art.
0
Mar 5, 2026
9.8
microsoft · CVE-2026-33824 — Windows Internet Key Exchange (IKE) Service Extensions Remote Code Execution VulnerabilityEXPLOITEDPATCHED
windows· CVSS 9.8· CWE-415
84
7 art.
0
Apr 14, 2026
8.8
microsoft · CVE-2026-21262 — SQL Server Elevation of Privilege VulnerabilityKEVEXPLOITEDPATCHED
sql_server_2016· CVSS 8.8· CWE-284
83
1 art.
0
Mar 10, 2026
10.0
axios · CVE-2026-40175 — Axios has Unrestricted Cloud Metadata Exfiltration via Header Injection ChainEXPLOITEDPATCHED
axios· CVSS 10.0· CWE-113
79
4 art.
0
Apr 10, 2026
→ View full list

Pre-CVE Events

View all
ZERO-DAYMalicious Code Injection via Axios npm Package Maintainer Account Takeover
axiosMEDIUM1 sourcesverified
ZERO-DAYADV990001 Latest Servicing Stack Updates
1 sourcesverified
Code Execution Vulnerability in vim
MEDIUM1 sources
Denial of Service Vulnerability in IBM Spectrum Protect Plus
ibmHIGH1 sources
Multiple Vulnerabilities in Kyverno Allow Information Disclosure, Security Bypass, Data Manipulation, and Privilege Escalation
HIGH1 sources

Latest news

View all
[B]adobeCVE-2026-27220
Security Alert: Alert Regarding Vulnerabilities in Adobe Acrobat and Reader (APSB26-26)
[B]microsoft
Security Alert: Microsoft Releases March 2026 Security Updates
[B]microsoftCVE-2026-32201
Security Alert: Microsoft Releases April 2026 Security Updates
[B]adobe
Security Alert: Alert Regarding Vulnerabilities in Adobe Acrobat and Reader (APSB25-119)
[B]microsoftCVE-2026-20805
Security Alert: Microsoft Releases January 2026 Security Updates
[B]microsoftCVE-2025-62221
Security Alert: Microsoft Releases December 2025 Security Updates
[B]microsoftCVE-2026-21510
Security Alert: Microsoft Releases February 2026 Security Updates
[B]adobe
Security Alert: Alert Regarding Vulnerabilities in Adobe Acrobat and Reader (APSB26-44)