Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4992 articles · 188948 vulns · 37/41 feeds (7d)

Trending Vulnerabilities

Top vulnerabilities ranked by news velocity, CISA KEV status, EPSS exploitation probability, and independent source coverage.

1
7.0
microsoft · CVE-2026-68820 — Windows Ancillary Function Driver for WinSock Elevation of Privilege VulnerabilityKEVEXPLOITEDPATCHED
windows 10 version· CVSS 7.0· CWE-416
155🔥
19 art.
0
Aug 11, 2026
2
9.1
microsoft · CVE-2026-55040 — Microsoft SharePoint Server Security Feature Bypass VulnerabilityKEVEXPLOITEDPATCHED
sharepoint_server· CVSS 9.1· CWE-1390
154🔥
18 art.
0
Jul 14, 2026
3
8.8
microsoft · CVE-2026-45659 — Microsoft SharePoint Remote Code Execution VulnerabilityKEVEXPLOITEDPATCHED
sharepoint_server· CVSS 8.8· CWE-502
153🔥
15 art.
0
May 22, 2026
4
9.8
VMware · CVE-2026-59310 — vCenter directory-traversal vulnerabilityKEVEXPLOITEDPATCHED
Cloud Foundation· CVSS 9.8· CWE-22
137🔥
7 art.
0
Jul 30, 2026
5
10.0
metaba · CVE-2026-72898 — Metabase SQL injection via password reset endpointKEVEXPLOITEDPATCHED
metaba· CVSS 10.0· CWE-89
120🔥
2 art.
0
Aug 10, 2026
6
9.8
wordpress · CVE-2026-63030 — WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code ExecutionKEVEXPLOITEDPATCHED
wordpress· CVSS 9.8
115🔥
22 art.
0
Jul 17, 2026
7
9.8
jetbrains · CVE-2026-63077 — CVE-2026-63077: In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent pollinKEVEXPLOITEDPATCHED
teamcity· CVSS 9.8· CWE-502
114🔥
12 art.
0
Jul 27, 2026
8
9.6
progress · CVE-2026-8037 — OS Command Injection Remote Code Execution Vulnerability in Progress LoadMaster, ECS Connection Manager, Object Scale Connection Manager & MOVEit WAFKEVEXPLOITEDPATCHED
connection_manager_for_objectscale· CVSS 9.6· CWE-77
106🔥
12 art.
0
Jun 4, 2026
9
9.8
langflow · CVE-2026-9198 — Unauthenticated Remote Code Execution via Auto-Login Bypass and Code ValidationKEVEXPLOITEDPATCHED
langflow· CVSS 9.8· CWE-94
106🔥
7 art.
0
Jul 17, 2026
10
5.9
wordpress · CVE-2026-60137 — WordPress < 7.0.2 - Facilitated SQL Injection via author__not_in in WP_QueryKEVEXPLOITEDPATCHED
wordpress· CVSS 5.9
103🔥
19 art.
0
Jul 17, 2026
11
7.8
microsoft · CVE-2026-50656 — Microsoft Defender Elevation of Privilege VulnerabilityEXPLOITEDPATCHED
malware_protection_engine· CVSS 7.8· CWE-59
97
19 art.
0
Jun 16, 2026
12
7.5
widgetfactory · CVE-2026-48907 — Joomla Extension - joomlacontenteditor.net - Remote Code Execution in JCE extension for Joomla < 2.9.99.5KEVEXPLOITED
jce· CVSS 7.5· CWE-284
97
6 art.
0
Jun 5, 2026
13
8.8
linux · CVE-2026-53359 — KVM: x86: Fix shadow paging use-after-free due to unexpected roleEXPLOITEDPATCHED
linux_kernel· CVSS 8.8
96
21 art.
0
Jul 4, 2026
14
7.1
apple · CVE-2026-65400 — CVE-2026-65400: An authentication issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.9, macOSKEVEXPLOITEDPATCHED
macos· CVSS 7.1· CWE-20
91
7 art.
0
Aug 6, 2026
15
9.8
blocksy · CVE-2026-58480 — Blocksy Companion Pro < 2.1.47 Unauthenticated File Upload via save_attachmentsKEVEXPLOITEDPATCHED
blocksy companion pro· CVSS 9.8· CWE-434
91
2 art.
0
Jul 8, 2026
16
10.0
sonicwall · CVE-2026-15409 — CVE-2026-15409: A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A EXPLOITEDPATCHED
sma6210_firmware· CVSS 10.0· CWE-918
88
24 art.
0
Jul 14, 2026
17
8.8
apache · CVE-2026-49975 — Apache HTTP Server: mod_http2 denial of serviceEXPLOITEDPATCHED
http_server· CVSS 8.8· CWE-789
87
13 art.
0
Jun 8, 2026
18
8.6
cis · CVE-2026-20349 — Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software Remote Access SSL VPN Denial of Service Vulnerability
cisco secure firewall adaptive security appliance (asa)· CVSS 8.6· CWE-244
79
7 art.
0
Aug 11, 2026
19
7.2
sonicwall · CVE-2026-15410 — CVE-2026-15410: Post-authentication improper control of generation of code ('Code Injection') vulnerability has been identified in the SEXPLOITEDPATCHED
sma6210_firmware· CVSS 7.2· CWE-94
78
24 art.
0
Jul 14, 2026
20
9.8
conductor-oss · CVE-2026-58138 — Orkes Conductor 3.21.21 < 3.30.2 Unauthenticated RCE via GraalVM Script EvaluatorsKEVEXPLOITEDPATCHED
conductor· CVSS 9.8· CWE-94
77
2 art.
0
Jun 30, 2026
21
9.8
microsoft · CVE-2026-50522 — Microsoft SharePoint Remote Code Execution VulnerabilityKEVEXPLOITEDPATCHED
sharepoint_server· CVSS 9.8· CWE-502
76
11 art.
0
Jul 14, 2026
22
5.3
microsoft · CVE-2026-56164 — Microsoft SharePoint Server Elevation of Privilege VulnerabilityKEVEXPLOITEDPATCHED
sharepoint_server· CVSS 5.3· CWE-306
75
21 art.
0
Jul 14, 2026
23
10.0
sap · CVE-2026-58231 — Improper Authorization in SAP Commerce Cloud (Data Hub Adapter)
sap commerce cloud (data hub adapter)· CVSS 10.0· CWE-94
68
6 art.
0
Aug 11, 2026
24
8.8
linux · CVE-2026-53360 — KVM: SEV: Require in-GHCB scratch area if GHCB v2+ is in useEXPLOITEDPATCHED
linux_kernel· CVSS 8.8
67
5 art.
0
Jul 4, 2026
25
10.0
microsoft · CVE-2026-65667 — Microsoft Teams Elevation of Privilege VulnerabilityPATCHED
teams· CVSS 10.0· CWE-862
66
6 art.
0
Aug 6, 2026
26
9.8
Microsoft · CVE-2026-59124 — Microsoft High Performance Computing (HPC) Pack Remote Code Execution VulnerabilityPATCHED
Windows App Client for Windows Desktop· CVSS 9.8· CWE-502
65
5 art.
0
Aug 11, 2026
27
9.8
Microsoft · CVE-2026-62893 — Windows Deployment Services TFTP Server Remote Code Execution VulnerabilityPATCHED
Windows 10 Version 1607· CVSS 9.8· CWE-416
65
5 art.
0
Aug 11, 2026
28
9.8
microsoft · CVE-2026-65791 — Windows iSCSI Target Service Remote Code Execution VulnerabilityPATCHED
windows 10 version· CVSS 9.8· CWE-122
65
5 art.
0
Aug 11, 2026
29
7.8
Microsoft · CVE-2026-62832 — Windows User Profile Service Elevation of Privilege VulnerabilityPATCHED
Windows 10 Version 21H2· CVSS 7.8· CWE-59
63
8 art.
0
Aug 11, 2026
30
10.0
microsoft · CVE-2026-56162 — Azure SQL Database Elevation of Privilege VulnerabilityPATCHED
azure_sql_database· CVSS 10.0· CWE-287
63
5 art.
0
Aug 6, 2026
31
9.1
adobe · CVE-2026-71362 — Adobe Commerce | Incorrect Authorization (CWE-863)PATCHED
adobe commerce· CVSS 9.1· CWE-863
62
4 art.
0
Aug 11, 2026
32
7.5
Cisco · CVE-2026-20337 — ClamAV ZIP File Format Processing Memory Corruption Vulnerability
Cisco Secure Endpoint· CVSS 7.5· CWE-120
62
8 art.
0
Aug 7, 2026
33
—
n-able · CVE-2026-18577 — Incomplete patch leads to administrative account takeoverPATCHED
n-central· CWE-288
62
13 art.
0
Aug 2, 2026
34
7.5
Cisco · CVE-2026-20338 — ClamAV ZIP File Format Processing Memory Corruption Vulnerability
Cisco Secure Endpoint· CVSS 7.5· CWE-415
62
8 art.
0
Aug 7, 2026
35
9.8
Microsoft · CVE-2026-62815 — Microsoft QUIC Remote Code Execution VulnerabilityPATCHED
Windows 11 version 23H2· CVSS 9.8· CWE-416
62
4 art.
0
Aug 11, 2026
36
10.0
adobe · CVE-2026-48362 — ColdFusion | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') (CWE-78)PATCHED
coldfusion· CVSS 10.0· CWE-78
62
4 art.
0
Aug 11, 2026
37
8.1
Microsoft · CVE-2026-63520 — Microsoft SharePoint Server Remote Code Execution VulnerabilityPATCHED
Microsoft SharePoint Enterprise Server 2016· CVSS 8.1· CWE-20
61
8 art.
0
Aug 11, 2026
38
6.5
dhcpcd-project · CVE-2026-14258 — Dhcpcd: dhcpcd infinite loop and out-of-bounds read via zero-length ipv6 nd option in router advertisement handlingEXPLOITEDPATCHED
dhcpcd· CVSS 6.5· CWE-835
60
3 art.
0
Jul 1, 2026
39
9.8
sap · CVE-2026-34265 — Memory Corruption vulnerability in Application Server ABAP for SAP NetWeaver and ABAP Platform
sap netweaver and abap platform· CVSS 9.8· CWE-787
60
5 art.
0
Aug 11, 2026
40
9.8
microsoft · CVE-2026-62873 — Microsoft 365 Admin Center Elevation of Privilege VulnerabilityPATCHED
windows_admin_center· CVSS 9.8· CWE-347
59
4 art.
0
Aug 6, 2026
41
9.1
sonicwall · CVE-2026-66145 — CVE-2026-66145: An unauthenticated remote code execution vulnerability was identified in GMS 9.5.1 (Build 9510.1044) and earlier versionPATCHED
gms· CVSS 9.1· CWE-94
58
3 art.
0
Aug 11, 2026
42
7.5
praisonai · CVE-2026-61447 — PraisonAI before 1.6.78 Remote Code Execution via CodeAgentEXPLOITEDPATCHED
praisonai· CVSS 7.5· CWE-94
58
2 art.
0
Jul 11, 2026
43
9.4
sonicwall · CVE-2026-66147 — CVE-2026-66147: An unauthenticated command injection vulnerability was identified in the GMS Dispatcher Service in GMS 9.5.1 and earlierPATCHED
gms· CVSS 9.4· CWE-94
58
3 art.
0
Aug 11, 2026
44
9.8
suyogs · CVE-2026-61459 — MCP Server Kubernetes < 3.9.0 Argument Injection via kubectl Structured ToolsEXPLOITEDPATCHED
mcp-server-kubernetes· CVSS 9.8· CWE-88
58
2 art.
0
Jul 10, 2026
45
7.5
microsoft · CVE-2026-62918 — Microsoft Teams Spoofing VulnerabilityPATCHED
teams· CVSS 7.5· CWE-347
58
6 art.
0
Aug 6, 2026
46
—
rubygems · CVE-2026-66066 — Action Pack: Possible arbitrary file read and remote code execution in Active Storage variant processingPATCHED
activestorage· CWE-1188
57
15 art.
0
Jul 30, 2026
47
7.5
Microsoft · CVE-2026-59132 — Windows TCP/IP Denial of Service VulnerabilityPATCHED
Windows 10 Version 1607· CVSS 7.5· CWE-476
57
5 art.
0
Aug 11, 2026
48
7.8
Microsoft · CVE-2026-62737 — Windows Kernel Elevation of Privilege VulnerabilityPATCHED
Windows 11 Version 24H2· CVSS 7.8· CWE-822
56
6 art.
0
Aug 11, 2026
49
9.9
microsoft · CVE-2026-50515 — Azure Service Bus Remote Code Execution VulnerabilityPATCHED
azure_service_bus· CVSS 9.9· CWE-502
56
6 art.
0
Aug 6, 2026
50
7.8
Microsoft · CVE-2026-65775 — Windows Win32k Elevation of Privilege VulnerabilityPATCHED
Windows 10 Version 1607· CVSS 7.8· CWE-416
56
6 art.
0
Aug 11, 2026