Critical Alert 4 Active Exploits Detected Today

CVE-2026-93952 Arista VeloCloud Orchestrator Improper Input Validation Vulnerability →
CVE-2026-94127 F5 BIG-IP APM Heap-based Buffer Overflow Vulnerability →
CVE-2026-93616 Check Point Multiple Products Path Traversal Vulnerability →
CVE-2026-85102 Check Point Multiple Products Improper Certificate Validation Vulnerability →
Powered by CVE Watchtower
×

CVE Watchtower

🔔 Premium Features
🔍 Filter Threats
📧Email Delivery — Threat intel straight to your inbox.
♾️Unlimited Vendors — Track your entire stack.
🚨All New CVEs — Be the first to know.
⚙️Custom EPSS — Filter noise, focus on risk.
💬Webhooks — Slack & Teams integration.
🚫Ad-Free — Uninterrupted experience.
📧Email Delivery — Threat intel straight to your inbox.
♾️Unlimited Vendors — Track your entire stack.
🚨All New CVEs — Be the first to know.
⚙️Custom EPSS — Filter noise, focus on risk.
💬Webhooks — Slack & Teams integration.
🚫Ad-Free — Uninterrupted experience.
Title
SeverityPoCActively ExploitedSourceDate
CVE-2026-87831
The Checkout Field Manager plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 7.9.6. This is due to a mis...
MEDIUM??????????Wordfence5 days ago
CVE-2026-87829
The Checkout Field Manager plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 7.9.6. This is...
MEDIUM??????????Wordfence5 days ago
CVE-2026-50605
A vulnerability has been identified in the Acer Agent Service component included with NitroSense and PredatorSense. Insufficient access controls withi...
UNKNOWN??????????NVD5 days ago
CVE-2026-86320
A flaw was found in flatpak-builder where Git hooks are not disabled when applying patch sources with use-git-am: true. An attacker who can provide a ...
HIGH??????????NVD5 days ago
CVE-2026-87963
The Yo WordPress plugin from 1.1 through 1.3.1 does not sanitize or parameterize the username request parameter before using it in a SQL query, and re...
HIGH??????????NVD5 days ago
CVE-2026-91017
The Robokassa payment gateway for Woocommerce plugin for WordPress is vulnerable to Payment Bypass in all versions up to, and including, 1.8.8. This i...
MEDIUM??????????Wordfence5 days ago
CVE-2026-86801
The To Do List Member plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions 1.4 to 1.6. This is due to insufficient input ...
HIGH??????????Wordfence5 days ago
CVE-2026-90982
@fastify/static is a Fastify plugin that serves static files from a configured root directory. In versions before 10.1.4, on a case-insensitive filesy...
MEDIUM??????????NVD5 days ago
CVE-2026-44940
The rancher-extension-stackstate extension in SUSE Observability exposes service tokens in plain configuration or insecure locations rather than manag...
MEDIUM??????????NVD5 days ago
CVE-2026-91019
The Event Booking Manager for WooCommerce plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 5.5.0. This ...
MEDIUM??????????Wordfence5 days ago
CVE-2026-91016
The Motors plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.4.120. This is due to missin...
MEDIUM??????????Wordfence5 days ago
CVE-2026-91015
The Master Addons for Elementor plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 3.1.8. This is due to ...
MEDIUM??????????Wordfence5 days ago
CVE-2026-91014
The Realtyna Organic IDX plugin + WPL Real Estate plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and incl...
MEDIUM??????????Wordfence5 days ago
CVE-2026-91011
The EWWW Image Optimizer plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 8.7.6. This is due to...
MEDIUM??????????Wordfence5 days ago
CVE-2026-91010
The Invisible Anti-Spam & CAPTCHA plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 5.1.0. This is d...
MEDIUM??????????Wordfence5 days ago
CVE-2026-91009
The Active Products Tables for WooCommerce plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 2.1.2. This...
MEDIUM??????????Wordfence5 days ago
CVE-2026-91008
The Event Booking Manager for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including,...
MEDIUM??????????Wordfence5 days ago
CVE-2026-90923
The Autopay plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 5.0.0. This is due to a missing capability...
MEDIUM??????????Wordfence5 days ago
CVE-2026-90922
The Paid Member Subscriptions plugin for WordPress is vulnerable to Payment Bypass in all versions up to, and including, 3.0.8. This is due to a lack ...
MEDIUM??????????Wordfence5 days ago
CVE-2026-88904
The PuppyFW plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 0.4.4. This is due to insufficient restri...
MEDIUM??????????Wordfence5 days ago
📧Email Delivery — Threat intel straight to your inbox.
♾️Unlimited Vendors — Track your entire stack.
🚨All New CVEs — Be the first to know.
⚙️Custom EPSS — Filter noise, focus on risk.
💬Webhooks — Slack & Teams integration.
🚫Ad-Free — Uninterrupted experience.
📧Email Delivery — Threat intel straight to your inbox.
♾️Unlimited Vendors — Track your entire stack.
🚨All New CVEs — Be the first to know.
⚙️Custom EPSS — Filter noise, focus on risk.
💬Webhooks — Slack & Teams integration.
🚫Ad-Free — Uninterrupted experience.