Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
2858 articles · 109942 vulns · 38/41 feeds (7d)
739
+83 today
Exploited (7d)
269
+53 today
Critical (7d)
1536
CISA KEV
5
Pre-CVE
2858
+506 today
Articles (7d)

Threat Briefing

Global

Loading...

About Zero Day Monitor

Open-source vulnerability intelligence for security teams. The platform scans 41 security feeds, analyzes articles with AI, and surfaces the threats that matter. Track trending CVEs, discover zero-days before they get a CVE ID, and monitor your vendor stack for supply-chain risks.

Trending
Ranked by source count
Zero-Days
Pre-CVE detection
Verification
Community-driven
Open Source
AGPL-3.0 licensed
Learn more about the projectSign in for personalized features

Vulnerabilities

8.8
google · CVE-2026-5281 — CVE-2026-5281: Use after free in Dawn in Google Chrome prior to 146.0.7680.178 allowed a remote attacker who had compromised the renderKEVEXPLOITEDPATCHED
chrome· CVSS 8.8· CWE-416
138🔥
15 art.
0
Apr 1, 2026
9.3
marimo · CVE-2026-39987 — marimo Affected by Pre-Auth Remote Code Execution via Terminal WebSocket Authentication BypassKEV
EXPLOITED
PATCHED
marimo· CVSS 9.3· CWE-306
118🔥
3 art.
0
Apr 8, 2026
9.8
ivanti · CVE-2026-1340 — CVE-2026-1340: A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution.KEVEXPLOITEDPATCHED
endpoint_manager_mobile· CVSS 9.8· CWE-94
116🔥
3 art.
0
Jan 29, 2026
9.1
fortinet · CVE-2026-35616 — CVE-2026-35616: A improper access control vulnerability in Fortinet FortiClientEMS 7.4.5 through 7.4.6 may allow an unauthenticated attaKEVEXPLOITEDPATCHED
forticlientems· CVSS 9.1· CWE-284
105🔥
17 art.
0
Apr 4, 2026
10.0
cis · CVE-2026-20127 — A vulnerability in the peering authentication in Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, and Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an unauthenticated, rKEVEXPLOITEDPATCHED
catalyst_sd-wan_manager· CVSS 10.0· CWE-287
96
1 art.
0
Feb 25, 2026
9.8
beyondtrust · CVE-2026-1731 — BeyondTrust Remote Support (RS) and certain older versions of Privileged Remote Access (PRA) contain a critical pre-authentication remote code execution vulnerability. By sending specially crafted reqKEVEXPLOITEDPATCHED
privileged_remote_access· CVSS 9.8· CWE-78
92
2 art.
0
Feb 6, 2026
9.8
ivanti · CVE-2026-1281 — A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution.KEVEXPLOITEDPATCHED
endpoint_manager_mobile· CVSS 9.8· CWE-94
89
2 art.
0
Jan 29, 2026
9.8
smart slider 3 · CVE-2026-34424 — Smart Slider 3 Pro 3.5.1.35 Supply Chain Attack Remote Access ToolkitKEVEXPLOITEDPATCHED
smart slider 3 pro· CVSS 9.8· CWE-506
88
1 art.
0
Apr 9, 2026
9.8
ninja forms · CVE-2026-0740 — Ninja Forms - File Upload <= 3.3.26 - Unauthenticated Arbitrary File UploadKEVEXPLOITED
file uploads· CVSS 9.8· CWE-434
87
3 art.
0
Apr 7, 2026
9.8
fortinet · CVE-2026-21643 — An improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiClientEMS 7.4.4 may allow an unauthenticated attacker to execute unauthorized codKEVEXPLOITEDPATCHED
forticlientems· CVSS 9.8· CWE-89
81
10 art.
0
Feb 6, 2026
→ View full list

Pre-CVE Events

View all
The Mythos Inflection Point: Dealing With the Upcoming Vulnerability Disclosure Avalanche and Compressed Exploitation Window
1 sources
systemd-journald Character Escaping Issue
systemdHIGH0 sources
[Video] The TTP Ep. 22: The Collapse of the Patch Window
1 sources
D-Link DIR-650IN - Authenticated Command Injection
d-link1 sources
Identity-based attacks exploiting stolen credentials
cisHIGH1 sources

Latest news

View all
[B]microsoftCVE-2026-21510
Security Alert: Microsoft Releases February 2026 Security Updates
[B]microsoft
Security Alert: Microsoft Releases March 2026 Security Updates
[B]microsoftCVE-2025-62221
Security Alert: Microsoft Releases December 2025 Security Updates
[B]microsoftCVE-2026-20805
Security Alert: Microsoft Releases January 2026 Security Updates
[B]adobe
Security Alert: Alert Regarding Vulnerabilities in Adobe Acrobat and Reader (APSB25-119)
[B]adobeCVE-2026-27220
Security Alert: Alert Regarding Vulnerabilities in Adobe Acrobat and Reader (APSB26-26)
[C]flatpakCVE-2026-40354
CVE-2026-40354 | Flatpak xdg-desktop-portal up to 1.20.3/1.21.0 g_file_trash symlink (GHSA-rqr9-jwwf-wxgj)
1h ago
[C]optimoleCVE-2026-5226
CVE-2026-5226 | Optimole Plugin up to 4.2.3 on WordPress get_current_url cross site scripting
1h ago