Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4505 articles · 223849 vulns · 37/41 feeds (7d)

Latest Security News

Recently analyzed articles from 41 RSS feeds across official advisories, government CERTs, security research, and community sources.

Tier A: Official
Tier B: Gov CERT
Tier C: Research
Tier D: News
Tier E: Community
Status:
AllAnalyzedQueuedSignal Only
C
CVE-2026-101105 | code-projects Matrimonial System 1.0 Profile Creation Endpoint /create_profile processprofile_form fname sql injection
VulDB·54m ago·cve_linking
C
CVE-2026-101102 | deepseek-ai deepseek-harness up to 0.1.0-rc.7 Code Mode Sandbox run_code sandbox
VulDB·1h ago·cve_linking
C
CVE-2026-101101 | ag-ui-protocol ag-ui up to 2026-09-07 Middleware legacy/convert.ts JSON.parse uncaught exception (Issue 2444)
VulDB·1h ago·cve_linking
C
CVE-2026-101100 | ag-ui-protocol ag-ui up to 2026-09-07 Middleware filter-tool-calls.ts FilterToolCallsMiddleware cleanup (Issue 2443)
VulDB·1h ago·cve_linking
C
CVE-2026-101099 | ag-ui-protocol ag-ui up to 2026-09-23 Kotlin Community SDK SseParser.kt exceptional condition (Issue 2442)
VulDB·1h ago·cve_linking
C
CVE-2026-101098 | ag-ui-protocol ag-ui up to 2026-09-23 HTTP JdkAgentHttpHandler.java readAllBytes resource consumption (Issue 2441)
VulDB·1h ago·cve_linking
C
CVE-2026-101083 | PMWeb v7.x/v8.x/v2025.x encryptionhelper.dll information disclosure
VulDB·9h ago·cve_linking
C
CVE-2026-101082 | PMWeb 7.x/8.x/2025.x downloader.aspx FullFileName/FileName path traversal
VulDB·9h ago·cve_linking
C
CVE-2026-101081 | D-Link DI-8400 16.07 Web Administration Service menu_nat_more.asp menu_nat_more_asp opt stack-based overflow
VulDB·10h ago·cve_linking
C
CVE-2026-101080 | Tencent AI-Infra-Guard up to 4.5.2/4.6.2 File Access dir_actions.py startsWith path traversal (Issue 538)
VulDB·10h ago·cve_linking
C
CVE-2026-101079 | agentverus agentverus-scanner up to 0.8.1 context.js isSecurityDefenseSkill reliance on untrusted inputs in a security decision (Issue 28)
VulDB·10h ago·cve_linking
C
CVE-2026-101078 | deepseek-ai deepseek-harness up to 0.1.7-rc.2 Landlock Backend profiles.ts isolation
VulDB·10h ago·cve_linking
C
CVE-2026-101077 | Netcore NR289-GE 1.4.5102 boa_temp process_request missing authentication
VulDB·10h ago·cve_linking
C
CVE-2026-101076 | Netcore NR289-GE 1.4.5102 CGI /set_ntp_server_ip.cgi system ntp_ip os command injection
VulDB·10h ago·cve_linking
C
CVE-2026-101075 | Netcore NR289-GE 1.4.5102 Location Time /location_time.cgi system mac os command injection
VulDB·10h ago·cve_linking
C
CVE-2026-101074 | Netcore NR289-GE 1.4.5102 Authentication /bin/boa password-check Username stack-based overflow
VulDB·10h ago·cve_linking
C
CVE-2026-101073 | Netcore NR289-GE 1.4.5102 CGI Dispatcher /bin/boa improper authentication
VulDB·10h ago·cve_linking
C
CVE-2026-101072 | Netcore NR289-GE 1.4.5102 CGI /ap_ip.cgi system ip os command injection
VulDB·10h ago·cve_linking
C
CVE-2026-101071 | Acrel Electric Unet Web Service up to 20260814 Upload Endpoint upload File unrestricted upload
VulDB·10h ago·cve_linking
C
CVE-2026-101070 | dbgate up to 7.3.1 Files Endpoint runners.js files runid path traversal
VulDB·11h ago·cve_linking
C
CVE-2026-101069 | dbgate up to 7.3.1 Export databaseConnections.js exportModelSql outputFile path traversal
VulDB·11h ago·cve_linking
C
CVE-2026-101068 | dbgate up to 7.3.1 Create Connection Endpoint zipJsonLinesData.js zipJsonLinesData filePath path traversal
VulDB·11h ago·cve_linking
C
CVE-2026-101067 | dbgate up to 7.3.1 save-uploaded-file Endpoint files.js saveUploadedFile filePath/fileName path traversal
VulDB·11h ago·cve_linking
C
CVE-2026-101066 | dbgate up to 7.3.1 Archive Link Creation archive.js createLink linkedFolder path traversal
VulDB·11h ago·cve_linking
C
CVE-2026-101055 | Thinkware U3000 up to 1.02.04 TCP Service GET_STATUS wifi_info information disclosure
VulDB·11h ago·cve_linking
C
CVE-2026-101054 | Thinkware U3000 up to 1.02.04 TCP Service /tmp/wpa_supplicant.conf get_file access control
VulDB·11h ago·cve_linking
C
CVE-2026-101053 | Thinkware U3000 up to 1.02.04 TCP Service /tmp/wpa_supplicant.conf PUT_FILE path access control
VulDB·11h ago·cve_linking
C
CVE-2026-101052 | refly-ai refly up to 1.1.0 JWT Token app.config.ts hard-coded credentials
VulDB·12h ago·cve_linking
C
CVE-2026-101040 | Ricoh SP 330DN/SP 221/SP C252SF//Aficio SP 3500SF up to 20260813 HTTP Multipart Form-Data Parser denial of service
VulDB·13h ago·cve_linking
C
CVE-2026-101039 | FAST FAC1900R 20190827_2.0.2 devdiscover Service copy_msg_element stack-based overflow
VulDB·13h ago·cve_linking
C
CVE-2026-101038 | FAST FAC1200R 5.0_20201119_1.0.2 MmtAtePrase Parser stack-based overflow
VulDB·13h ago·cve_linking
C
CVE-2026-101037 | FAST FAC1200R 5.0_20201119_1.0.2 devdiscover Service parse_advertisement_frame stack-based overflow
VulDB·13h ago·cve_linking
C
CVE-2026-101036 | FLB-Music FLB-Music-Player 1.1.8/1.1.9/1.2.0/1.2.1 createParsedTrack.ts path.join path traversal
VulDB·14h ago·cve_linking
C
CVE-2026-101035 | aligungr UERANSIM up to 3.3.0 nr-gnb src/lib/nas/encode.cpp DecodePlainMmMessage uncaught exception
VulDB·14h ago·cve_linking
C
CVE-2026-101018 | dayrui XunruiCMS up to 4.7.2 Group Editing Home.php group_all_edit groupid sql injection
VulDB·16h ago·cve_linking
C
CVE-2026-101017 | Trusted Domain Project OpenDMARC up to 1.4.2 opendmarc_policy.c strcasecmp exceptional condition
VulDB·16h ago·cve_linking
C
CVE-2026-101016 | Trusted Domain Project OpenDMARC up to 1.4.2 opendmarc_policy.c opendmarc_policy_parse_dmarc fo/rf/ri/pct/sp/adkim/aspf/rua/ruf exceptional condition
VulDB·16h ago·cve_linking
C
CVE-2026-101015 | Trusted Domain Project OpenDMARC up to 1.4.2 policy.c improper validation of unsafe equivalence in input
VulDB·16h ago·cve_linking
C
CVE-2026-101014 | Trusted Domain Project OpenDMARC up to 1.4.2 DMARC Record Parser opendmarc_util.c opendmarc_util_cleanup off-by-one (ID 188)
VulDB·16h ago·cve_linking
C
CVE-2026-101013 | mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be updateresultdetails.php editid sql injection
VulDB·17h ago·cve_linking
C
CVE-2026-101012 | mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be makeresult.php makeid sql injection
VulDB·17h ago·cve_linking
C
CVE-2026-101011 | aaPanel BaoTa up to 11.8.0 Domain domainMod.py get_domain_status get sql injection
VulDB·17h ago·cve_linking
C
CVE-2026-101010 | aaPanel BaoTa up to 11.8.0 data.py getData log_type sql injection
VulDB·17h ago·cve_linking
C
CVE-2026-101009 | aaPanel BaoTa up to 11.8.0 Unzip panelTask.py panelTask.bt_task._unzip Password os command injection
VulDB·17h ago·cve_linking
C
CVE-2026-101008 | aaPanel BaoTa up to 11.8.0 File Merge files.py merge_split_file split_file_path command injection
VulDB·17h ago·cve_linking
C
CVE-2026-101007 | aaPanel BaoTa up to 11.8.0 Database Backup class/database.py InputSql Password os command injection
VulDB·17h ago·cve_linking
C
CVE-2026-101006 | Frappe HR up to 16.15.0 Permission Validation hrms/api/__init__.py employee authorization
VulDB·17h ago·cve_linking
C
CVE-2026-101005 | October CMS up to 4.3.4 SSRF Protection ResizeImages.php validateExternalImageHost server-side request forgery (GHSA-j2j7-7m99-6226)
VulDB·17h ago·cve_linking
C
CVE-2026-101004 | notionnext-org NotionNext up to 4.10.10 Authentication Guard pages/api/cache.js cleanCache token missing authentication
VulDB·17h ago·cve_linking
C
CVE-2026-101003 | Cesanta Mongoose up to 7.21 MQTT Broker main.c fn stack-based overflow
VulDB·17h ago·cve_linking
Articles are automatically fetched from RSS feeds, pre-filtered for security relevance, and analyzed by LLM for vulnerability extraction. View feed sources