August 29, 2026

CVE Watchtower

Advanced Threat Data Export

Filter and download the raw CVE repository (CSV/JSON) for SIEM integration and internal reporting.

Data export is locked. Upgrade your package to enable filtering and downloading.

🔔 Premium Features
🔍 Filter Threats
Title
SeverityPoCActively ExploitedSourceDate
???-????-????
??????????????????????????????????
??????????????????????????????????
CRITICAL??????????SA20 hours ago
???-????-????
??????????????????????????????????
??????????????????????????????????
HIGH??????????SA20 hours ago
???-????-????
??????????????????????????????????
??????????????????????????????????
HIGH??????????SA3 days ago
???-????-????
??????????????????????????????????
??????????????????????????????????
CRITICAL??????????SA4 days ago
???-????-????
??????????????????????????????????
??????????????????????????????????
CRITICAL??????????SA7 days ago
CVE-2026-14494
The Sigma Forms Pro plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.4.5 via the handle_form_submis...
CRITICAL??????????NVD1 hour ago
CVE-2026-82449
Cockpit CMS before 2.14.1 contains an account enumeration vulnerability in the auth check endpoint due to timing discrepancies in password verificatio...
MEDIUM??????????NVD1 hour ago
CVE-2026-82448
Shinobi before commit 5a76c74f contains a hardcoded connection key in the child node service that allows unauthenticated attackers to execute arbitrar...
CRITICAL??????????NVD1 hour ago
CVE-2026-82447
Skyvern before 1.0.45 contains a sandbox escape vulnerability in TextPromptBlock that renders prompts twice, first through a sandboxed Jinja environme...
HIGH??????????NVD1 hour ago
CVE-2026-82364
A security vulnerability has been detected in macrozheng mall up to 1.0.3. This impacts an unknown function of the file /order/submit of the component...
MEDIUM??????????NVD2 hours ago
CVE-2026-80725
In the Linux kernel, the following vulnerability has been resolved: net: gro: properly validate BIG TCP aggregation criteria When GRO attempts to ag...
UNKNOWN??????????NVD6 hours ago
CVE-2026-81346
The Frontend Admin by DynamiApps WordPress plugin before 3.29.11 does not perform a capability check on one of its AJAX actions, allowing any authenti...
UNKNOWN??????????NVD7 hours ago
CVE-2026-81342
The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.43 does not validate a redirect parameter supplied during user registration before u...
UNKNOWN??????????NVD7 hours ago
CVE-2026-81200
The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.42 does not correctly restrict access to order information, allowing any user with t...
UNKNOWN??????????NVD7 hours ago
CVE-2026-81026
The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.40 does not verify the amount, receiver, currency or status of a payment notificatio...
UNKNOWN??????????NVD7 hours ago
CVE-2026-80488
The WP Ultimate CSV Importer WordPress plugin before 9.0 does not properly sanitise and escape imported field values before using them in a SQL state...
UNKNOWN??????????NVD7 hours ago
CVE-2026-80311
The Stripe Payment Forms by WP Full Pay WordPress plugin before 8.5.5 does not verify that a subscription belongs to the customer bound to the reques...
UNKNOWN??????????NVD7 hours ago
CVE-2026-77786
The Rank Math SEO WordPress plugin before 1.0.277 does not check that the user requesting an automated SEO fix holds the capability WordPress itself ...
UNKNOWN??????????NVD7 hours ago
CVE-2026-77704
The Booking for Appointments and Events Calendar WordPress plugin before 2.4.9 does not check that a user holds the required capability before lettin...
UNKNOWN??????????NVD7 hours ago
CVE-2026-77012
The 爱采集数据采集和发布插件 WordPress plugin through 1.0.0 does not require a per-install secret for one of its unauthenticated endpoints...
UNKNOWN??????????NVD7 hours ago
CVE-2026-77010
The HEL Online Classroom: AI-powered Online Classrooms WordPress plugin through 1.0.3 does not perform authorisation checks on its REST API routes and...
UNKNOWN??????????NVD7 hours ago
CVE-2026-77008
The HEL Online Classroom: AI-powered Online Classrooms WordPress plugin through 1.0.3 does not have any authorisation or authentication check when sav...
UNKNOWN??????????NVD7 hours ago
CVE-2026-77007
The HEL Online Classroom: AI-powered Online Classrooms WordPress plugin through 1.0.3 does not perform any authorisation check on one of its REST API ...
UNKNOWN??????????NVD7 hours ago
CVE-2026-76586
The Appointment Booking Calendar Plugin and Scheduling Plugin WordPress plugin before 1.6.3 does not verify the amount actually paid against the serv...
UNKNOWN??????????NVD7 hours ago
CVE-2026-76548
The User Profile Builder WordPress plugin before 4.0.1 does not properly restrict its front-end file upload feature, granting unauthenticated visitor...
UNKNOWN??????????NVD7 hours ago