Latest zero-days Total: 397, in 2018: Zero-days 21, candidates: 9

Arbitrary file upload in jQuery File Upload plugin
CVE-2018-9206

The vulnerability is publicly known since at least 2015.

Privilege escalation in Microsoft Windows Win32k
CVE-2018-8453

HEUR:Exploit.Win32.Generic
HEUR:Trojan.Win32.Generic
PDM:Exploit.Win32.Generic

According to Kaspersky Lab, the vulnerability is being actively exploited by the FruityArmor APT actor.

Spoofing attack in Apple Safari

Not patched

Vulnerability in Apple Safari was used to bypass browser security restrictions and upload malware to vulnerable systems, according to DarkMatter LLC report.

The attack is believed to be carried out by the WindShift APT actor against government organizations in the Middle East.

Privilege escalation in Microsoft Windows
CVE-2018-8440

A privilege escalation vulnerability was first publicly disclosed on Twitter on August 27, 2018. It was successful incorporated into malware used by the PowerPool group, reported by ESET.
The vulnerability was dubbed SendboxEscaper by its author.

Vulnerability Scanning SaaS

Vulnerability scanning SaaS service is online 3-rd generation vulnerability scanner with scheduled assessments and vulnerability subscription. You can use service to check security of your network perimeter.