Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
3018 articles · 157069 vulns · 36/41 feeds (7d)
528
+83 today
Exploited (7d)
264
+62 today
Critical (7d)
1630
CISA KEV
133
Pre-CVE
3018
+962 today
Articles (7d)

Threat Briefing

Global

Loading...

About Zero Day Monitor

Open-source vulnerability intelligence for security teams. The platform scans 41 security feeds, analyzes articles with AI, and surfaces the threats that matter. Track trending CVEs, discover zero-days before they get a CVE ID, and monitor your vendor stack for supply-chain risks.

Trending
Ranked by source count
Zero-Days
Pre-CVE detection
Verification
Community-driven
Open Source
AGPL-3.0 licensed
Learn more about the projectSign in for personalized features

Vulnerabilities

9.1
fortinet · CVE-2026-35616 — CVE-2026-35616: A improper access control vulnerability in Fortinet FortiClientEMS 7.4.5 through 7.4.6 may allow an unauthenticated attaKEVEXPLOITEDPATCHED
forticlientems· CVSS 9.1· CWE-284
170🔥
20 art.
0
Apr 4, 2026
7.8
microsoft · CVE-2026-33825 — Microsoft Defender Elevation of Privilege VulnerabilityKEVEXPLOITEDPATCHED
defender_antimalware_platform· CVSS 7.8· CWE-1220
158🔥
20 art.
0
Apr 14, 2026
7.8
microsoft · CVE-2026-41091 — Microsoft Defender Elevation of Privilege VulnerabilityKEVEXPLOITEDPATCHED
malware_protection_engine· CVSS 7.8· CWE-59
157🔥
15 art.
0
May 20, 2026
8.8
linux · CVE-2026-43284 — xfrm: esp: avoid in-place decrypt on shared skb fragsKEVEXPLOITEDPATCHED
linux_kernel· CVSS 8.8
142🔥
31 art.
0
May 8, 2026
7.8
linux · CVE-2026-43500 — rxrpc: Also unshare DATA/RESPONSE packets when paged frags are presentKEVEXPLOITEDPATCHED
linux_kernel· CVSS 7.8· CWE-20
137🔥
15 art.
0
May 11, 2026
4.0
microsoft · CVE-2026-45498 — Microsoft Defender Denial of Service VulnerabilityKEVEXPLOITEDPATCHED
defender_antimalware_platform· CVSS 4.0· CWE-400
137🔥
8 art.
0
May 20, 2026
9.8
drupal · CVE-2026-9082 — Drupal core - Highly critical - SQL injection - SA-CORE-2026-004KEVEXPLOITEDPATCHED
drupal· CVSS 9.8· CWE-89
120🔥
14 art.
0
May 20, 2026
10.0
litespeedtech · CVE-2026-48172 — CVE-2026-48172: LiteSpeed User-End cPanel Plugin before 2.4.5 allows privilege escalation (possibly to root), as exploited in the wild iKEVEXPLOITEDPATCHED
litespeed_cpanel_plugin· CVSS 10.0· CWE-266
116🔥
4 art.
0
May 21, 2026
7.8
linux · CVE-2026-31431 — crypto: algif_aead - Revert to operating out-of-placeKEVEXPLOITEDPATCHED
linux_kernel· CVSS 7.8
116🔥
82 art.
0
Apr 22, 2026
9.8
cpanel · CVE-2026-41940 — WebPros cPanel and WHM Authentication Bypass via Login FlowKEVEXPLOITEDPATCHED
cpanel· CVSS 9.8· CWE-306
112🔥
23 art.
0
Apr 29, 2026
→ View full list

Pre-CVE Events

View all
ZERO-DAYMalicious Code Injection via Axios npm Package Maintainer Account Takeover
axiosMEDIUM1 sourcesverified
ZERO-DAYADV990001 Latest Servicing Stack Updates
1 sourcesverified
Critical Arbitrary PHP Code Execution in Drupal AlternativeCommerce (Basket)
drupalCRITICAL1 sources
Multiple vulnerabilities in Veeam Backup and Recovery Orchestrator products
veeam1 sources
Multiple vulnerabilities in Zimbra Daffodil prior to v10.1.17
zimbra1 sources

Latest news

View all
[B]microsoftCVE-2025-62221
Security Alert: Microsoft Releases December 2025 Security Updates
[B]microsoft
Security Alert: Microsoft Releases May 2026 Security Updates
[B]adobe
Security Alert: Alert Regarding Vulnerabilities in Adobe Acrobat and Reader (APSB25-119)
[B]microsoft
Security Alert: Microsoft Releases March 2026 Security Updates
[B]microsoftCVE-2026-20805
Security Alert: Microsoft Releases January 2026 Security Updates
[B]microsoftCVE-2026-32201
Security Alert: Microsoft Releases April 2026 Security Updates
[B]adobe
Security Alert: Alert Regarding Vulnerabilities in Adobe Acrobat and Reader (APSB26-44)
[B]microsoftCVE-2026-21510
Security Alert: Microsoft Releases February 2026 Security Updates