Critical Alert 4 Active Exploits Detected Today

CVE-2026-93952 Arista VeloCloud Orchestrator Improper Input Validation Vulnerability →
CVE-2026-94127 F5 BIG-IP APM Heap-based Buffer Overflow Vulnerability →
CVE-2026-93616 Check Point Multiple Products Path Traversal Vulnerability →
CVE-2026-85102 Check Point Multiple Products Improper Certificate Validation Vulnerability →
Powered by CVE Watchtower
×

CVE Watchtower

🔔 Premium Features
🔍 Filter Threats
📧Email Delivery — Threat intel straight to your inbox.
♾️Unlimited Vendors — Track your entire stack.
🚨All New CVEs — Be the first to know.
⚙️Custom EPSS — Filter noise, focus on risk.
💬Webhooks — Slack & Teams integration.
🚫Ad-Free — Uninterrupted experience.
📧Email Delivery — Threat intel straight to your inbox.
♾️Unlimited Vendors — Track your entire stack.
🚨All New CVEs — Be the first to know.
⚙️Custom EPSS — Filter noise, focus on risk.
💬Webhooks — Slack & Teams integration.
🚫Ad-Free — Uninterrupted experience.
Title
SeverityPoCActively ExploitedSourceDate
CVE-2026-66572
The JetBlog plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 2.4.10. This is due to insufficien...
MEDIUM??????????Wordfence5 days ago
CVE-2026-66571
The Asset CleanUp: Page Speed Booster plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.4.0.5. ...
MEDIUM??????????Wordfence5 days ago
CVE-2026-62108
The Headless SSO Plugin for WP plugin for WordPress is vulnerable to Account Takeover in all versions up to, and including, 1.7.0. This is due to a fl...
HIGH??????????Wordfence5 days ago
CVE-2026-62104
The Migratico Lite plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.6.8. This is due to insufficien...
CRITICAL??????????Wordfence5 days ago
CVE-2026-62101
The EduAdmin Booking plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 5.4.2. This makes it p...
MEDIUM??????????Wordfence5 days ago
CVE-2026-90986
The Visitor Traffic Real Time Statistics pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 1...
HIGH??????????Wordfence5 days ago
CVE-2026-85500
Authentication Bypass by Primary Weakness vulnerability in team-alembic AshAuthentication allows an unconfirmed user to obtain a session, defeating a ...
UNKNOWN??????????NVD5 days ago
CVE-2026-86533
Insufficient Session Expiration vulnerability in team-alembic AshAuthentication and AshAuthentication Phoenix allows a revoked session to remain fully...
UNKNOWN??????????NVD5 days ago
CVE-2026-81632
Use of HTTP Request With Sensitive Query String vulnerability in team-alembic AshAuthenticationPhoenix allows someone able to read access logs, proxy ...
UNKNOWN??????????NVD5 days ago
CVE-2026-80218
Improper Authentication vulnerability in team-alembic AshAuthentication allows an attacker holding a sign-in token for one authenticated resource to b...
UNKNOWN??????????NVD5 days ago
CVE-2026-78223
Improper Verification of Cryptographic Signature vulnerability in team-alembic AshAuthentication allows a caller of the token revocation action to neu...
UNKNOWN??????????NVD5 days ago
CVE-2026-86522
Improper Output Neutralization for Logs vulnerability in team-alembic AshAuthentication allows an unauthenticated attacker to forge application log en...
UNKNOWN??????????NVD5 days ago
CVE-2026-81637
Insufficient Session Expiration vulnerability in team-alembic AshAuthentication allows an attacker who obtains a victim's OAuth2 state value to r...
UNKNOWN??????????NVD5 days ago
CVE-2026-82761
Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in team-alembic AshAuthentication allows an attacker holding a leaked magic link to re...
UNKNOWN??????????NVD5 days ago
CVE-2026-82685
Authorization Bypass Through User-Controlled Key vulnerability in team-alembic AshAuthentication allows an authenticated attacker to overwrite and con...
UNKNOWN??????????NVD5 days ago
CVE-2026-82760
Inefficient Algorithmic Complexity vulnerability in team-alembic AshAuthentication allows an unauthenticated attacker to exhaust CPU and memory via an...
UNKNOWN??????????NVD5 days ago
CVE-2026-82759
Use of a One-Way Hash with a Predictable Salt vulnerability in team-alembic AshAuthentication allows readers of the audit store to recover the client ...
UNKNOWN??????????NVD5 days ago
CVE-2026-82723
Insertion of Sensitive Information into Log File vulnerability in team-alembic AshAuthentication allows disclosure of user password digests to readers...
UNKNOWN??????????NVD5 days ago
CVE-2026-53679
No description available
UNKNOWN??????????NVD5 days ago
CVE-2026-11874
No description available
UNKNOWN??????????NVD5 days ago
📧Email Delivery — Threat intel straight to your inbox.
♾️Unlimited Vendors — Track your entire stack.
🚨All New CVEs — Be the first to know.
⚙️Custom EPSS — Filter noise, focus on risk.
💬Webhooks — Slack & Teams integration.
🚫Ad-Free — Uninterrupted experience.
📧Email Delivery — Threat intel straight to your inbox.
♾️Unlimited Vendors — Track your entire stack.
🚨All New CVEs — Be the first to know.
⚙️Custom EPSS — Filter noise, focus on risk.
💬Webhooks — Slack & Teams integration.
🚫Ad-Free — Uninterrupted experience.