Critical Alert 4 Active Exploits Detected Today

CVE-2026-93952 Arista VeloCloud Orchestrator Improper Input Validation Vulnerability →
CVE-2026-94127 F5 BIG-IP APM Heap-based Buffer Overflow Vulnerability →
CVE-2026-93616 Check Point Multiple Products Path Traversal Vulnerability →
CVE-2026-85102 Check Point Multiple Products Improper Certificate Validation Vulnerability →
Powered by CVE Watchtower
×

CVE Watchtower

🔔 Premium Features
🔍 Filter Threats
📧Email Delivery — Threat intel straight to your inbox.
♾️Unlimited Vendors — Track your entire stack.
🚨All New CVEs — Be the first to know.
⚙️Custom EPSS — Filter noise, focus on risk.
💬Webhooks — Slack & Teams integration.
🚫Ad-Free — Uninterrupted experience.
📧Email Delivery — Threat intel straight to your inbox.
♾️Unlimited Vendors — Track your entire stack.
🚨All New CVEs — Be the first to know.
⚙️Custom EPSS — Filter noise, focus on risk.
💬Webhooks — Slack & Teams integration.
🚫Ad-Free — Uninterrupted experience.
Title
SeverityPoCActively ExploitedSourceDate
CVE-2026-92940
vm2 versions 3.11.3 through 3.11.6 expose the host process's real https.globalAgent to sandboxed code when a NodeVM is explicitly configured to a...
CRITICAL??????????NVD5 days ago
CVE-2026-92939
vm2 3.11.3 through 3.11.6 exposes the host Node.js crypto module to a NodeVM sandbox when the crypto builtin is allowed. The module is presented via a...
CRITICAL??????????NVD5 days ago
CVE-2026-92938
vm2 versions 3.11.3 through 3.11.6 expose Node.js's host node:sqlite module to code running in NodeVM when that builtin is permitted, either expl...
CRITICAL??????????NVD5 days ago
CVE-2026-92937
vm2 3.11.6 is vulnerable to a sandbox escape leading to remote code execution in the host Node.js process. The fix for GHSA-m283-3h24-438v is incomple...
CRITICAL??????????NVD5 days ago
CVE-2026-92936
vm2 versions 3.11.0 through 3.11.6 leak absolute host filesystem paths to sandboxed code through error stack formatting. Attacker-supplied code can fo...
MEDIUM??????????NVD5 days ago
CVE-2026-92935
vm2 is a sandbox for running untrusted Node.js code. In versions >= 3.11.4 and <= 3.11.6, the NodeVM constructor computes `hasRealRequireConfig`...
CRITICAL??????????NVD5 days ago
CVE-2026-92934
vm2 before 3.11.8 contains an incomplete fix for Error.cause sanitization that allows sandbox escape when revisited host-wrapped AggregateError object...
CRITICAL??????????NVD5 days ago
CVE-2026-92933
vm2 is a sandbox for running untrusted Node.js code. In versions <= 3.11.7, NodeVM exposes the host `util` module to the sandbox as an unfiltered s...
MEDIUM??????????NVD5 days ago
CVE-2026-92973
ansi2html versions 1.7.0a0 through 1.9.3 contain a cross-site scripting vulnerability in OSC 8 hyperlink handling that fails to validate or escape URL...
MEDIUM??????????NVD5 days ago
CVE-2026-92972
SGLang through 0.5.19 in prefill/decode disaggregation mode contains an unauthenticated PUT /route endpoint on the prefill bootstrap service that allo...
HIGH??????????NVD5 days ago
CVE-2026-92971
InternLM LMDeploy through 0.17.0 contains a reachable assertion vulnerability in the DistServe decode migration loop that allows unauthenticated attac...
HIGH??????????NVD5 days ago
CVE-2026-92970
HUBzero CMS through 2.2.32 contains a path traversal vulnerability in project file upload handlers that allows authenticated project members to write ...
HIGH??????????NVD5 days ago
CVE-2026-80355
Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Cross-Site Request Forgery (CSRF) vulnerability. An unauthenticated attac...
MEDIUM??????????NVD5 days ago
CVE-2026-89418
google-protobuf contains an unbounded recursion when parsing unknown protobuf group fields. An attacker can send a small crafted payload of deeply nes...
UNKNOWN??????????NVD5 days ago
CVE-2026-14850
The password reset funcionality is vulnerable to unauthorized account modification due to improper validation of the user_id parameter. An attacker ca...
UNKNOWN??????????NVD5 days ago
CVE-2026-90887
The WP Inventory Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 2.5.4. This is due to...
HIGH??????????Wordfence5 days ago
CVE-2026-78528
The BerqWP – All-In-One Optimization for Core Web Vitals, Cache, CDN, Images, CSS & JavaScript plugin for WordPress is vulnerable to unauthorize...
MEDIUM??????????Wordfence5 days ago
CVE-2026-78295
The Xagio SEO & AEO – AI SEO for Google Rankings & AI Visibility plugin for WordPress is vulnerable to Cross-Site Request Forgery in all ver...
MEDIUM??????????Wordfence5 days ago
CVE-2026-78294
The Geo Mashup plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 1.13.21. This is due to insuffi...
MEDIUM??????????Wordfence5 days ago
CVE-2026-74017
The User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration &am...
MEDIUM??????????Wordfence5 days ago
📧Email Delivery — Threat intel straight to your inbox.
♾️Unlimited Vendors — Track your entire stack.
🚨All New CVEs — Be the first to know.
⚙️Custom EPSS — Filter noise, focus on risk.
💬Webhooks — Slack & Teams integration.
🚫Ad-Free — Uninterrupted experience.
📧Email Delivery — Threat intel straight to your inbox.
♾️Unlimited Vendors — Track your entire stack.
🚨All New CVEs — Be the first to know.
⚙️Custom EPSS — Filter noise, focus on risk.
💬Webhooks — Slack & Teams integration.
🚫Ad-Free — Uninterrupted experience.