Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
2976 articles · 110830 vulns · 36/41 feeds (7d)
769
+206 today
Exploited (7d)
163
+67 today
Critical (7d)
1543
CISA KEV
15
Pre-CVE
2976
+742 today
Articles (7d)

Threat Briefing

Global

Loading...

About Zero Day Monitor

Open-source vulnerability intelligence for security teams. The platform scans 41 security feeds, analyzes articles with AI, and surfaces the threats that matter. Track trending CVEs, discover zero-days before they get a CVE ID, and monitor your vendor stack for supply-chain risks.

Trending
Ranked by source count
Zero-Days
Pre-CVE detection
Verification
Community-driven
Open Source
AGPL-3.0 licensed
Learn more about the projectSign in for personalized features

Vulnerabilities

9.1
fortinet · CVE-2026-21643 — CVE-2026-21643: An improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiCKEVEXPLOITEDPATCHED
forticlientems· CVSS 9.1· CWE-89
152🔥
13 art.
0
Feb 6, 2026
6.5
Microsoft · CVE-2026-32201 — Microsoft SharePoint Server Spoofing VulnerabilityKEVEXPLOITED
PATCHED
Microsoft SharePoint Enterprise Server 2016· CVSS 6.5· CWE-20
151🔥
6 art.
0
Apr 14, 2026
8.6
adobe · CVE-2026-34621 — Acrobat Reader | Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') (CWE-1321)KEVEXPLOITEDPATCHED
acrobat_dc· CVSS 8.6· CWE-1321
146🔥
14 art.
0
Apr 11, 2026
9.8
fortinet · CVE-2026-35616 — CVE-2026-35616: A improper access control vulnerability in Fortinet FortiClientEMS 7.4.5 through 7.4.6 may allow an unauthenticated attaKEVEXPLOITEDPATCHED
forticlientems· CVSS 9.8· CWE-284
131🔥
18 art.
0
Apr 4, 2026
9.3
marimo · CVE-2026-39987 — marimo Affected by Pre-Auth Remote Code Execution via Terminal WebSocket Authentication BypassKEVEXPLOITEDPATCHED
marimo· CVSS 9.3· CWE-306
113🔥
6 art.
0
Apr 8, 2026
10.0
axios · CVE-2026-40175 — Axios has Unrestricted Cloud Metadata Exfiltration via Header Injection ChainEXPLOITEDPATCHED
axios· CVSS 10.0· CWE-113
83
2 art.
0
Apr 10, 2026
8.8
openclaw · CVE-2026-25253 — OpenClaw (aka clawdbot or Moltbot) before 2026.1.29 obtains a gatewayUrl value from a query string and automatically makes a WebSocket connection without prompting, sending a token value.KEVEXPLOITEDPATCHED
openclaw· CVSS 8.8· CWE-669
82
1 art.
0
Feb 1, 2026
9.8
gnu · CVE-2026-24061 — telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment variable.KEVEXPLOITEDPATCHED
inetutils· CVSS 9.8· CWE-88
81
1 art.
0
Jan 21, 2026
8.8
google · CVE-2026-5281 — CVE-2026-5281: Use after free in Dawn in Google Chrome prior to 146.0.7680.178 allowed a remote attacker who had compromised the renderKEVEXPLOITEDPATCHED
chrome· CVSS 8.8· CWE-416
80
15 art.
0
Apr 1, 2026
9.1
Fortinet · CVE-2026-39813 — CVE-2026-39813: A path traversal: '../filedir' vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.EXPLOITEDPATCHED
FortiSandbox· CVSS 9.1· CWE-24
74
2 art.
0
Apr 14, 2026
→ View full list

Pre-CVE Events

View all
ZERO-DAYMalicious Code Injection via Axios npm Package Maintainer Account Takeover
axiosMEDIUM1 sourcesverified
ZERO-DAYADV990001 Latest Servicing Stack Updates
1 sourcesverified
Multiple critical vulnerabilities in Tenable Identity Exposure
tenableCRITICAL1 sources
Multiple Vulnerabilities in Various Adobe Products
adobe1 sources
Multiple Critical Vulnerabilities in Fortinet Products Including OS Command Injection, Authentication Bypass, Privilege Escalation, Heap-based Buffer Overflow, and SQL Injection
fortinetCRITICAL1 sources

Latest news

View all
[B]adobe
Security Alert: Alert Regarding Vulnerabilities in Adobe Acrobat and Reader (APSB25-119)
[B]microsoftCVE-2026-21510
Security Alert: Microsoft Releases February 2026 Security Updates
[B]microsoftCVE-2026-20805
Security Alert: Microsoft Releases January 2026 Security Updates
[B]microsoft
Security Alert: Microsoft Releases March 2026 Security Updates
[B]adobeCVE-2026-27220
Security Alert: Alert Regarding Vulnerabilities in Adobe Acrobat and Reader (APSB26-26)
[B]microsoftCVE-2025-62221
Security Alert: Microsoft Releases December 2025 Security Updates
[C]octobercmsCVE-2026-25133
CVE-2026-25133 | October LMS up to 3.7.13/4.1.9 SVG File Parser cross site scripting (GHSA-gcqv-f29m-67gr)
44m ago
[C]chamiloCVE-2026-34161
CVE-2026-34161 | Chamilo LMS up to 2.0.0-RC.2 social_post_attachments cross site scripting (GHSA-273p-jw9w-3g22)
44m ago