Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
2543 articles · 104590 vulns · 38/41 feeds (7d)
413
+42 today
Exploited (7d)
249
+34 today
Critical (7d)
1527
CISA KEV
10
Pre-CVE
2543
+333 today
Articles (7d)

Threat Briefing

Global

Loading...

About Zero Day Monitor

Open-source vulnerability intelligence for security teams. The platform scans 41 security feeds, analyzes articles with AI, and surfaces the threats that matter. Track trending CVEs, discover zero-days before they get a CVE ID, and monitor your vendor stack for supply-chain risks.

Trending
Ranked by source count
Zero-Days
Pre-CVE detection
Verification
Community-driven
Open Source
AGPL-3.0 licensed
Learn more about the projectSign in for personalized features

Vulnerabilities

9.1
fortinet · CVE-2026-35616 — CVE-2026-35616: A improper access control vulnerability in Fortinet FortiClientEMS 7.4.5 through 7.4.6 may allow an unauthenticated attaKEVEXPLOITEDPATCHED
forticlientems· CVSS 9.1· CWE-284
160🔥
13 art.
0
Apr 4, 2026
8.8
google · CVE-2026-5281 — CVE-2026-5281: Use after free in Dawn in Google Chrome prior to 146.0.7680.178 allowed a remote attacker who had compromised the renderKEV
EXPLOITED
PATCHED
chrome· CVSS 8.8· CWE-416
141🔥
12 art.
0
Apr 1, 2026
7.8
trueconf · CVE-2026-3502 — TrueConf Client Update Integrity Verification BypassKEVEXPLOITED
trueconf· CVSS 7.8· CWE-494
129🔥
7 art.
1
Mar 30, 2026
9.8
fortinet · CVE-2026-21643 — An improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiClientEMS 7.4.4 may allow an unauthenticated attacker to execute unauthorized codKEVEXPLOITEDPATCHED
forticlientems· CVSS 9.8· CWE-89
117🔥
8 art.
0
Feb 6, 2026
9.8
smartertools · CVE-2026-23760 — SmarterTools SmarterMail versions prior to build 9511 contain an authentication bypass vulnerability in the password reset API. The force-reset-password endpoint permits anonymous requests and fails tKEVEXPLOITEDPATCHED
smartermail· CVSS 9.8· CWE-288
111🔥
2 art.
0
Jan 22, 2026
9.8
beyondtrust · CVE-2026-1731 — BeyondTrust Remote Support (RS) and certain older versions of Privileged Remote Access (PRA) contain a critical pre-authentication remote code execution vulnerability. By sending specially crafted reqKEVEXPLOITEDPATCHED
privileged_remote_access· CVSS 9.8· CWE-78
99
2 art.
0
Feb 6, 2026
—
tukaani · CVE-2026-34743 — XZ Utils: Buffer overflow in lzma_index_append()EXPLOITEDPATCHED
xz utils· CWE-122
73
5 art.
0
Mar 31, 2026
5.3
roundcube · CVE-2026-35544 — CVE-2026-35544: An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Insufficient Cascading Style Sheets (CSS) sanitizEXPLOITEDPATCHED
roundcube webmail· CVSS 5.3· CWE-669
72
4 art.
0
Apr 3, 2026
8.8
google · CVE-2026-3909 — Out of bounds write in Skia in Google Chrome prior to 146.0.7680.75 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)KEVEXPLOITEDPATCHED
chrome· CVSS 8.8· CWE-787
68
4 art.
0
Mar 13, 2026
8.8
google · CVE-2026-3910 — Inappropriate implementation in V8 in Google Chrome prior to 146.0.7680.75 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: HiKEVEXPLOITEDPATCHED
chrome· CVSS 8.8· CWE-94
68
4 art.
0
Mar 13, 2026
→ View full list

Pre-CVE Events

View all
Why Every Enterprise Needs a Risk Operations Center (ROC)
1 sources
CrowdStrike Enhances Vulnerability Response with Continuous Visibility
1 sources
New Mexico’s Meta Ruling and Encryption
1 sources
RiteCMS 3.1.0 Authenticated Remote Code Execution
handylulu1 sources
WBCE CMS 1.6.4 Remote Code Execution via Droplets Module
wbceCRITICAL1 sources

Latest news

View all
[B]microsoftCVE-2026-20805
Security Alert: Microsoft Releases January 2026 Security Updates
[B]microsoft
Security Alert: Microsoft Releases March 2026 Security Updates
[B]adobeCVE-2026-27220
Security Alert: Alert Regarding Vulnerabilities in Adobe Acrobat and Reader (APSB26-26)
[B]adobe
Security Alert: Alert Regarding Vulnerabilities in Adobe Acrobat and Reader (APSB25-119)
[B]microsoftCVE-2025-62221
Security Alert: Microsoft Releases December 2025 Security Updates
[B]microsoftCVE-2026-21510
Security Alert: Microsoft Releases February 2026 Security Updates
[A]python software foundationCVE-2026-34591
CVE-2026-34591 Poetry Has Wheel Path Traversal Which Can Lead to Arbitrary File Write
8m ago
[A]red hatCVE-2026-3184
CVE-2026-3184 Util-linux: util-linux: access control bypass due to improper hostname canonicalization
8m ago