Zero Day Monitor
ZDM
Dashboard
Vulnerabilities
Trending
Zero-Days
News
About
Login
All types
CVE only
Pre-CVE only
CISA KEV only
All severities
Critical
High
Medium
Low
More filters
Trending
Newest
Urgent
Critical Only
Weekly Urgent
Weekly Trending
139,618 vulnerabilities total
9.8
cpanel ·
CVE-2026-41940 —
WebPros cPanel and WHM Authentication Bypass via Login Flow
KEV
EXPLOITED
PATCHED
cpanel
· CVSS 9.8
· CWE-306
167
🔥
20 art.
0
Apr 29, 2026
7.0
ivanti ·
CVE-2026-6973 —
CVE-2026-6973: An Improper Input Validation in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remotely authentic
KEV
EXPLOITED
PATCHED
endpoint_manager_mobile
· CVSS 7.0
· CWE-20
140
🔥
12 art.
0
May 7, 2026
9.8
ivanti ·
CVE-2026-1340 —
CVE-2026-1340: A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution.
KEV
EXPLOITED
PATCHED
endpoint_manager_mobile
· CVSS 9.8
· CWE-94
137
🔥
8 art.
0
Jan 29, 2026
8.8
linux ·
CVE-2026-43284 —
xfrm: esp: avoid in-place decrypt on shared skb frags
KEV
EXPLOITED
PATCHED
linux_kernel
· CVSS 8.8
· CWE-20
135
🔥
17 art.
0
May 8, 2026
9.8
litellm ·
CVE-2026-42208 —
LiteLLM: SQL injection in Proxy API key verification
KEV
EXPLOITED
PATCHED
litellm
· CVSS 9.8
· CWE-89
127
🔥
5 art.
0
Apr 24, 2026
7.8
linux ·
CVE-2026-31431 —
crypto: algif_aead - Revert to operating out-of-place
KEV
EXPLOITED
PATCHED
linux_kernel
· CVSS 7.8
· CWE-20
122
🔥
66 art.
0
Apr 22, 2026
7.8
Linux ·
CVE-2026-43500 —
rxrpc: Also unshare DATA/RESPONSE packets when paged frags are present
KEV
EXPLOITED
PATCHED
Linux
· CVSS 7.8
118
🔥
4 art.
0
May 11, 2026
9.8
ivanti ·
CVE-2026-1281 —
A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution.
KEV
EXPLOITED
PATCHED
endpoint_manager_mobile
· CVSS 9.8
· CWE-94
110
🔥
7 art.
0
Jan 29, 2026
10.0
facebook ·
CVE-2025-55182 —
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 including the following packages: react-server-dom-parcel, react-
KEV
EXPLOITED
PATCHED
react
· CVSS 10.0
· CWE-502
96
17 art.
0
Dec 3, 2025
7.5
palo alto networks ·
CVE-2026-0300 —
PAN-OS: Unauthenticated user initiated Buffer Overflow Vulnerability in User-ID™ Authentication Portal
EXPLOITED
PATCHED
pan-os
· CVSS 7.5
· CWE-787
93
8 art.
0
May 6, 2026
9.8
progress ·
CVE-2026-4670 —
Improper Authentication vulnerability in Progress MOVEit Automation
EXPLOITED
PATCHED
moveit_automation
· CVSS 9.8
· CWE-305
88
10 art.
0
Apr 30, 2026
7.2
apache ·
CVE-2019-0193 —
In Apache Solr, the DataImportHandler, an optional but popular module to pull in data from databases and other sources, has a feature in which the whole DIH configuration can come from a request's "da
KEV
EXPLOITED
PATCHED
solr
· CVSS 7.2
· CWE-94
87
1 art.
0
Aug 1, 2019
7.5
apache ·
CVE-2019-17558 —
Apache Solr 5.0.0 to Apache Solr 8.3.1 are vulnerable to a Remote Code Execution through the VelocityResponseWriter. A Velocity template can be provided through Velocity templates in a configset `velo
KEV
EXPLOITED
PATCHED
solr
· CVSS 7.5
· CWE-74
87
1 art.
0
Dec 30, 2019
9.8
go toolchain ·
CVE-2026-27143 —
Missing bound checks can lead to memory corruption in safe Go in cmd/compile
EXPLOITED
PATCHED
cmd/compile
· CVSS 9.8
78
5 art.
0
Apr 8, 2026
9.1
spring ·
CVE-2026-40982 —
CVE-2026-40982: Spring Cloud Config allows applications to serve arbitrary text and binary files through the spring-cloud-config-server
EXPLOITED
PATCHED
spring cloud config
· CVSS 9.1
· CWE-22
76
5 art.
0
May 7, 2026
7.7
progress ·
CVE-2026-5174 —
Improper Access Control Vulnerability in Progress MOVEit Automation
EXPLOITED
PATCHED
moveit_automation
· CVSS 7.7
· CWE-20
73
8 art.
0
Apr 30, 2026
9.8
mozilla ·
CVE-2026-8091 —
Incorrect boundary conditions in the Audio/Video: Playback component
EXPLOITED
PATCHED
firefox
· CVSS 9.8
72
3 art.
0
May 7, 2026
8.8
google ·
CVE-2026-7896 —
CVE-2026-7896: Integer overflow in Blink in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to potentially exploit heap
EXPLOITED
PATCHED
chrome
· CVSS 8.8
· CWE-472
70
6 art.
0
May 6, 2026
5.3
axios ·
CVE-2026-42034 —
Axios: HTTP adapter streamed uploads bypass maxBodyLength when maxRedirects: 0
EXPLOITED
PATCHED
axios
· CVSS 5.3
· CWE-770
69
2 art.
0
Apr 24, 2026
7.5
golang ·
CVE-2026-32283 —
Unauthenticated TLS 1.3 KeyUpdate record can cause persistent connection retention and DoS in crypto/tls
EXPLOITED
PATCHED
go
· CVSS 7.5
68
5 art.
0
Apr 8, 2026
Load more