Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4501 articles · 223844 vulns · 37/41 feeds (7d)
220,824 vulnerabilities total
9.8
checkpoint · CVE-2026-85102 — Improper Certificate Validation in Quantum Security GatewayKEVEXPLOITED
gaia_embedded· CVSS 9.8· CWE-295
153🔥
15 art.
0
Sep 9, 2026
9.8
checkpoint · CVE-2026-93616 — Directory Traversal and File upload allows execution of arbitrary script on the Management ServerKEVEXPLOITED
multi-domain_security_management· CVSS 9.8· CWE-22
149🔥
10 art.
0
Sep 22, 2026
9.8
oracle · CVE-2026-35273 — CVE-2026-35273: Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Updates Environment ManaKEVEXPLOITEDPATCHED
peoplesoft_enterprise_peopletools· CVSS 9.8
143🔥
34 art.
0
Jun 11, 2026
8.1
WordPress · CVE-2026-87902 — CVE-2026-87902: An unauthenticated attacker can make `get_page_template()` page-template resolution include a chosen readable local `.phKEVEXPLOITEDPATCHED
WordPress· CVSS 8.1· CWE-98
141🔥
13 art.
0
Sep 22, 2026
8.8
zyxel · CVE-2026-7273 — CVE-2026-7273: A stack-based buffer overflow vulnerability in the CGI program of Zyxel GS1900-48HPv2 firmware versions through 2.90(ABTKEVEXPLOITEDPATCHED
gs1900-8_firmware· CVSS 8.8· CWE-121
132🔥
8 art.
0
Jun 16, 2026
—
citrix netscaler · CVE-2026-88771 — A remote code execution vulnerability exists due to improper input validation, which can allow an unauthenticated attacker to execute arbitrary commandsKEVEXPLOITEDPATCHED
adc· CWE-20
125🔥
2 art.
0
Sep 27, 2026
9.8
f5 · CVE-2026-94127 — BIG-IP APM OAuth vulnerabilityKEVEXPLOITEDPATCHED
big-ip_access_policy_manager· CVSS 9.8· CWE-122
118🔥
13 art.
0
Sep 22, 2026
—
citrix netscaler · CVE-2026-88772 — Memory overflow vulnerability leading to Remote Code Execution or Denial of ServiceKEVEXPLOITEDPATCHED
adc· CWE-119
115🔥
2 art.
0
Sep 27, 2026
10.0
gitlab · CVE-2026-85706 — Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in GitLabKEVEXPLOITEDPATCHED
gitlab· CVSS 10.0· CWE-22
112🔥
9 art.
0
Sep 12, 2026
9.1
adobe · CVE-2026-71362 — Adobe Commerce | Incorrect Authorization (CWE-863)KEVEXPLOITEDPATCHED
commerce· CVSS 9.1· CWE-863
110🔥
8 art.
0
Aug 11, 2026
9.8
issabel foundation · CVE-2026-89026 — Issabel Framework Hard-coded JWT Key RCE via pbxapi/manager/originateKEVEXPLOITEDPATCHED
issabel framework· CVSS 9.8· CWE-321
105🔥
3 art.
0
Sep 15, 2026
10.0
cis · CVE-2026-76460 — Cisco Identity Services Engine Authentication Bypass VulnerabilityKEVEXPLOITED
identity_services_engine· CVSS 10.0· CWE-648
105🔥
17 art.
0
Sep 16, 2026
9.8
jetbrains · CVE-2026-63077 — CVE-2026-63077: In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent pollinKEVEXPLOITEDPATCHED
teamcity· CVSS 9.8· CWE-502
100
14 art.
0
Jul 27, 2026
10.0
arista · CVE-2026-93952 — Security Advisory 0183KEVEXPLOITEDPATCHED
velocloud_orchestrator· CVSS 10.0· CWE-20
97
8 art.
0
Sep 22, 2026
7.8
linux · CVE-2026-53362 — ipv6: account for fraggap on the paged allocation pathKEVEXPLOITEDPATCHED
linux_kernel· CVSS 7.8
94
15 art.
0
Jul 4, 2026
10.0
sonicwall · CVE-2026-83548 — CVE-2026-83548: A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended alternKEVEXPLOITEDPATCHED
sma8200v· CVSS 10.0· CWE-918
90
19 art.
0
Sep 1, 2026
7.8
sonicwall · CVE-2026-83549 — CVE-2026-83549: Post-authentication Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerabiKEVEXPLOITEDPATCHED
sma8200v· CVSS 7.8· CWE-78
82
14 art.
0
Sep 1, 2026
—
mikrotik · CVE-2026-86060 — SSH session privilege manipulation via a crafted username in Mikrotik RouterOSKEVEXPLOITEDPATCHED
routeros· CWE-88
82
10 art.
0
Sep 5, 2026
—
citrix · CVE-2026-19490 — NetScaler ADC and NetScaler Gateway Security Bulletin for CVE-2026-19490
netscaler_application_delivery_controller
81
15 art.
0
Aug 19, 2026
9.8
apple · CVE-2026-65400 — CVE-2026-65400: An authentication issue was addressed with improved state management. This issue is fixed in macOS Golden Gate 27, macOSKEVEXPLOITEDPATCHED
macos· CVSS 9.8
80
23 art.
0
Aug 6, 2026