Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
2994 articles · 105164 vulns · 36/41 feeds (7d)
538
+117 today
Exploited (7d)
276
+86 today
Critical (7d)
1532
CISA KEV
15
Pre-CVE
2994
+482 today
Articles (7d)

Threat Briefing

Global

Loading...

About Zero Day Monitor

Open-source vulnerability intelligence for security teams. The platform scans 41 security feeds, analyzes articles with AI, and surfaces the threats that matter. Track trending CVEs, discover zero-days before they get a CVE ID, and monitor your vendor stack for supply-chain risks.

Trending
Ranked by source count
Zero-Days
Pre-CVE detection
Verification
Community-driven
Open Source
AGPL-3.0 licensed
Learn more about the projectSign in for personalized features

Vulnerabilities

9.1
fortinet · CVE-2026-35616 — CVE-2026-35616: A improper access control vulnerability in Fortinet FortiClientEMS 7.4.5 through 7.4.6 may allow an unauthenticated attaKEVEXPLOITEDPATCHED
forticlientems· CVSS 9.1· CWE-284
166🔥
17 art.
0
Apr 4, 2026
8.8
google · CVE-2026-5281 — CVE-2026-5281: Use after free in Dawn in Google Chrome prior to 146.0.7680.178 allowed a remote attacker who had compromised the renderKEV
EXPLOITED
PATCHED
chrome· CVSS 8.8· CWE-416
148🔥
14 art.
0
Apr 1, 2026
9.8
fortinet · CVE-2026-21643 — An improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiClientEMS 7.4.4 may allow an unauthenticated attacker to execute unauthorized codKEVEXPLOITEDPATCHED
forticlientems· CVSS 9.8· CWE-89
129🔥
10 art.
0
Feb 6, 2026
9.8
saturdaydrive · CVE-2026-0740 — Ninja Forms - File Upload <= 3.3.26 - Unauthenticated Arbitrary File UploadKEVEXPLOITED
ninja forms - file uploads· CVSS 9.8· CWE-434
126🔥
2 art.
0
Apr 7, 2026
7.8
trueconf · CVE-2026-3502 — TrueConf Client Update Integrity Verification BypassKEVEXPLOITED
trueconf· CVSS 7.8· CWE-494
118🔥
7 art.
1
Mar 30, 2026
9.8
weaver network co. · CVE-2026-22679 — Weaver E-cology 10.0 Unauthenticated RCE via dubboApi Debug EndpointKEVEXPLOITEDPATCHED
e-cology· CVSS 9.8· CWE-306
107🔥
1 art.
0
Apr 7, 2026
9.8
smartertools · CVE-2026-23760 — SmarterTools SmarterMail versions prior to build 9511 contain an authentication bypass vulnerability in the password reset API. The force-reset-password endpoint permits anonymous requests and fails tKEVEXPLOITEDPATCHED
smartermail· CVSS 9.8· CWE-288
101🔥
2 art.
0
Jan 22, 2026
9.8
beyondtrust · CVE-2026-1731 — BeyondTrust Remote Support (RS) and certain older versions of Privileged Remote Access (PRA) contain a critical pre-authentication remote code execution vulnerability. By sending specially crafted reqKEVEXPLOITEDPATCHED
privileged_remote_access· CVSS 9.8· CWE-78
91
1 art.
0
Feb 6, 2026
9.1
microsoft · CVE-2026-32211 — Azure MCP Server Information Disclosure VulnerabilityEXPLOITEDPATCHED
azure_web_apps· CVSS 9.1· CWE-306
75
3 art.
0
Apr 2, 2026
10.0
microsoft · CVE-2026-32213 — Azure AI Foundry Elevation of Privilege VulnerabilityEXPLOITEDPATCHED
azure_ai_foundry· CVSS 10.0· CWE-285
75
3 art.
0
Apr 2, 2026
→ View full list

Pre-CVE Events

View all
Anthropic Claude Mythos Preview: The More Capable AI Becomes, the More Security It Needs
1 sources
Bypass of AWS AgentCore Sandbox Isolation
amazon web servicesCRITICAL1 sources
Denial of Service Vulnerability in libarchive
MEDIUM1 sources
Critical vulnerabilities in VMware Tanzu MySQL for Kubernetes prior to version 2.0.2
vmwareCRITICAL1 sources
Netbeans Command Injection in Vim
vimMEDIUM1 sources

Latest news

View all
[B]microsoftCVE-2026-20805
Security Alert: Microsoft Releases January 2026 Security Updates
[B]microsoftCVE-2026-21510
Security Alert: Microsoft Releases February 2026 Security Updates
[B]microsoft
Security Alert: Microsoft Releases March 2026 Security Updates
[B]adobe
Security Alert: Alert Regarding Vulnerabilities in Adobe Acrobat and Reader (APSB25-119)
[B]adobeCVE-2026-27220
Security Alert: Alert Regarding Vulnerabilities in Adobe Acrobat and Reader (APSB26-26)
[B]microsoftCVE-2025-62221
Security Alert: Microsoft Releases December 2025 Security Updates
[D]saturdaydriveCVE-2026-0740
Hackers exploit critical flaw in Ninja Forms WordPress plugin
1h ago
[C]amazon web services
Cracks in the Bedrock: Escaping the AWS AgentCore Sandbox
1h ago