Zero Day Monitor
ZDM
Dashboard
Vulnerabilities
Trending
Zero-Days
News
About
Login
All types
CVE only
Pre-CVE only
CISA KEV only
All severities
Critical
High
Medium
Low
More filters
Trending
Newest
Urgent
Critical Only
Weekly Urgent
Weekly Trending
220,824 vulnerabilities total
9.8
checkpoint ·
CVE-2026-85102 —
Improper Certificate Validation in Quantum Security Gateway
KEV
EXPLOITED
gaia_embedded
· CVSS 9.8
· CWE-295
153
🔥
15 art.
0
Sep 9, 2026
9.8
checkpoint ·
CVE-2026-93616 —
Directory Traversal and File upload allows execution of arbitrary script on the Management Server
KEV
EXPLOITED
multi-domain_security_management
· CVSS 9.8
· CWE-22
149
🔥
10 art.
0
Sep 22, 2026
9.8
oracle ·
CVE-2026-35273 —
CVE-2026-35273: Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Updates Environment Mana
KEV
EXPLOITED
PATCHED
peoplesoft_enterprise_peopletools
· CVSS 9.8
143
🔥
34 art.
0
Jun 11, 2026
8.1
WordPress ·
CVE-2026-87902 —
CVE-2026-87902: An unauthenticated attacker can make `get_page_template()` page-template resolution include a chosen readable local `.ph
KEV
EXPLOITED
PATCHED
WordPress
· CVSS 8.1
· CWE-98
141
🔥
13 art.
0
Sep 22, 2026
8.8
zyxel ·
CVE-2026-7273 —
CVE-2026-7273: A stack-based buffer overflow vulnerability in the CGI program of Zyxel GS1900-48HPv2 firmware versions through 2.90(ABT
KEV
EXPLOITED
PATCHED
gs1900-8_firmware
· CVSS 8.8
· CWE-121
132
🔥
8 art.
0
Jun 16, 2026
—
citrix netscaler ·
CVE-2026-88771 —
A remote code execution vulnerability exists due to improper input validation, which can allow an unauthenticated attacker to execute arbitrary commands
KEV
EXPLOITED
PATCHED
adc
· CWE-20
125
🔥
2 art.
0
Sep 27, 2026
9.8
f5 ·
CVE-2026-94127 —
BIG-IP APM OAuth vulnerability
KEV
EXPLOITED
PATCHED
big-ip_access_policy_manager
· CVSS 9.8
· CWE-122
118
🔥
13 art.
0
Sep 22, 2026
—
citrix netscaler ·
CVE-2026-88772 —
Memory overflow vulnerability leading to Remote Code Execution or Denial of Service
KEV
EXPLOITED
PATCHED
adc
· CWE-119
115
🔥
2 art.
0
Sep 27, 2026
10.0
gitlab ·
CVE-2026-85706 —
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in GitLab
KEV
EXPLOITED
PATCHED
gitlab
· CVSS 10.0
· CWE-22
112
🔥
9 art.
0
Sep 12, 2026
9.1
adobe ·
CVE-2026-71362 —
Adobe Commerce | Incorrect Authorization (CWE-863)
KEV
EXPLOITED
PATCHED
commerce
· CVSS 9.1
· CWE-863
110
🔥
8 art.
0
Aug 11, 2026
9.8
issabel foundation ·
CVE-2026-89026 —
Issabel Framework Hard-coded JWT Key RCE via pbxapi/manager/originate
KEV
EXPLOITED
PATCHED
issabel framework
· CVSS 9.8
· CWE-321
105
🔥
3 art.
0
Sep 15, 2026
10.0
cis ·
CVE-2026-76460 —
Cisco Identity Services Engine Authentication Bypass Vulnerability
KEV
EXPLOITED
identity_services_engine
· CVSS 10.0
· CWE-648
105
🔥
17 art.
0
Sep 16, 2026
9.8
jetbrains ·
CVE-2026-63077 —
CVE-2026-63077: In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent pollin
KEV
EXPLOITED
PATCHED
teamcity
· CVSS 9.8
· CWE-502
100
14 art.
0
Jul 27, 2026
10.0
arista ·
CVE-2026-93952 —
Security Advisory 0183
KEV
EXPLOITED
PATCHED
velocloud_orchestrator
· CVSS 10.0
· CWE-20
97
8 art.
0
Sep 22, 2026
7.8
linux ·
CVE-2026-53362 —
ipv6: account for fraggap on the paged allocation path
KEV
EXPLOITED
PATCHED
linux_kernel
· CVSS 7.8
94
15 art.
0
Jul 4, 2026
10.0
sonicwall ·
CVE-2026-83548 —
CVE-2026-83548: A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended altern
KEV
EXPLOITED
PATCHED
sma8200v
· CVSS 10.0
· CWE-918
90
19 art.
0
Sep 1, 2026
7.8
sonicwall ·
CVE-2026-83549 —
CVE-2026-83549: Post-authentication Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerabi
KEV
EXPLOITED
PATCHED
sma8200v
· CVSS 7.8
· CWE-78
82
14 art.
0
Sep 1, 2026
—
mikrotik ·
CVE-2026-86060 —
SSH session privilege manipulation via a crafted username in Mikrotik RouterOS
KEV
EXPLOITED
PATCHED
routeros
· CWE-88
82
10 art.
0
Sep 5, 2026
—
citrix ·
CVE-2026-19490 —
NetScaler ADC and NetScaler Gateway Security Bulletin for CVE-2026-19490
netscaler_application_delivery_controller
81
15 art.
0
Aug 19, 2026
9.8
apple ·
CVE-2026-65400 —
CVE-2026-65400: An authentication issue was addressed with improved state management. This issue is fixed in macOS Golden Gate 27, macOS
KEV
EXPLOITED
PATCHED
macos
· CVSS 9.8
80
23 art.
0
Aug 6, 2026
Load more