Critical Alert 4 Active Exploits Detected Today

CVE-2026-93952 Arista VeloCloud Orchestrator Improper Input Validation Vulnerability →
CVE-2026-94127 F5 BIG-IP APM Heap-based Buffer Overflow Vulnerability →
CVE-2026-93616 Check Point Multiple Products Path Traversal Vulnerability →
CVE-2026-85102 Check Point Multiple Products Improper Certificate Validation Vulnerability →
Powered by CVE Watchtower
×

CVE Watchtower

🔔 Premium Features
🔍 Filter Threats
📧Email Delivery — Threat intel straight to your inbox.
♾️Unlimited Vendors — Track your entire stack.
🚨All New CVEs — Be the first to know.
⚙️Custom EPSS — Filter noise, focus on risk.
💬Webhooks — Slack & Teams integration.
🚫Ad-Free — Uninterrupted experience.
📧Email Delivery — Threat intel straight to your inbox.
♾️Unlimited Vendors — Track your entire stack.
🚨All New CVEs — Be the first to know.
⚙️Custom EPSS — Filter noise, focus on risk.
💬Webhooks — Slack & Teams integration.
🚫Ad-Free — Uninterrupted experience.
Title
SeverityPoCActively ExploitedSourceDate
CVE-2026-73999
The Cooked – Recipe Management plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.16.0. ...
MEDIUM??????????Wordfence5 days ago
CVE-2026-66676
The Easy Invoice – Invoice Generator, PDF Quotes & Payments plugin for WordPress is vulnerable to unauthorized access in all versions up to, and...
MEDIUM??????????Wordfence5 days ago
CVE-2026-66631
The MoreConvert Wishlist for WooCommerce plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 1.9.21. This is due...
MEDIUM??????????Wordfence5 days ago
CVE-2026-66630
The Issues and Series for Newspapers, Magazines, Publishers, Writers plugin for WordPress is vulnerable to SQL Injection in all versions up to, and in...
MEDIUM??????????Wordfence5 days ago
CVE-2026-66628
The WP-Lister Lite for eBay plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 3.8.11. This is due to insuffici...
MEDIUM??????????Wordfence5 days ago
CVE-2026-66626
The SKT Addons for Elementor plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 4.0. This is due to insufficien...
MEDIUM??????????Wordfence5 days ago
CVE-2026-66625
The WC Vendors – WooCommerce Multivendor, WooCommerce Marketplace, Product Vendors plugin for WordPress is vulnerable to SQL Injection in all versio...
MEDIUM??????????Wordfence5 days ago
CVE-2026-66624
The WPMasterToolKit (WPMTK) – All in one plugin plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 2.22.0. Th...
MEDIUM??????????Wordfence5 days ago
CVE-2026-66619
The Newsletters plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 4.18. This is due to insufficient escaping o...
MEDIUM??????????Wordfence5 days ago
CVE-2026-66618
The WP Maps – Google Maps,OpenStreetMap,Mapbox,Store Locator,Listing,Directory & Filters plugin for WordPress is vulnerable to SQL Injection in ...
MEDIUM??????????Wordfence5 days ago
CVE-2026-66617
The Issues and Series for Newspapers, Magazines, Publishers, Writers plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions...
MEDIUM??????????Wordfence5 days ago
CVE-2026-66608
The Unlimited Elements For Elementor plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.0.19. T...
MEDIUM??????????Wordfence5 days ago
CVE-2026-66580
The Product Feed Manager for WooCommerce – RexFeed – Sell on 200+ Shopping Channels plugin for WordPress is vulnerable to SQL Injection in all ver...
MEDIUM??????????Wordfence5 days ago
CVE-2026-66579
The JetElements plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 2.9.2.1. This is due to insuff...
MEDIUM??????????Wordfence5 days ago
CVE-2026-66578
The Property Hive plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 2.2.6. This is due to insuff...
MEDIUM??????????Wordfence5 days ago
CVE-2026-66577
The JetSearch plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 3.6.3. This is due to insufficie...
MEDIUM??????????Wordfence5 days ago
CVE-2026-66576
The JetBlocks for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 1.5.2. This is due...
MEDIUM??????????Wordfence5 days ago
CVE-2026-66575
The King Addons for Elementor – 100+ Elementor Widgets, 4 000+ Elementor Templates, WooCommerce Builder, Mega Menu, Popup Builder plugin for WordPre...
MEDIUM??????????Wordfence5 days ago
CVE-2026-66574
The Element Pack Addons for Elementor – Elementor Widgets, Elementor Templates, Elementor Addons plugin for WordPress is vulnerable to Stored Cross-...
MEDIUM??????????Wordfence5 days ago
CVE-2026-66573
The JetTabs plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 2.3.3.1. This is due to insufficie...
MEDIUM??????????Wordfence5 days ago
📧Email Delivery — Threat intel straight to your inbox.
♾️Unlimited Vendors — Track your entire stack.
🚨All New CVEs — Be the first to know.
⚙️Custom EPSS — Filter noise, focus on risk.
💬Webhooks — Slack & Teams integration.
🚫Ad-Free — Uninterrupted experience.
📧Email Delivery — Threat intel straight to your inbox.
♾️Unlimited Vendors — Track your entire stack.
🚨All New CVEs — Be the first to know.
⚙️Custom EPSS — Filter noise, focus on risk.
💬Webhooks — Slack & Teams integration.
🚫Ad-Free — Uninterrupted experience.