Critical Alert 4 Active Exploits Detected Today

CVE-2026-93952 Arista VeloCloud Orchestrator Improper Input Validation Vulnerability →
CVE-2026-94127 F5 BIG-IP APM Heap-based Buffer Overflow Vulnerability →
CVE-2026-93616 Check Point Multiple Products Path Traversal Vulnerability →
CVE-2026-85102 Check Point Multiple Products Improper Certificate Validation Vulnerability →
Powered by CVE Watchtower
×

CVE Watchtower

🔔 Premium Features
🔍 Filter Threats
📧Email Delivery — Threat intel straight to your inbox.
♾️Unlimited Vendors — Track your entire stack.
🚨All New CVEs — Be the first to know.
⚙️Custom EPSS — Filter noise, focus on risk.
💬Webhooks — Slack & Teams integration.
🚫Ad-Free — Uninterrupted experience.
📧Email Delivery — Threat intel straight to your inbox.
♾️Unlimited Vendors — Track your entire stack.
🚨All New CVEs — Be the first to know.
⚙️Custom EPSS — Filter noise, focus on risk.
💬Webhooks — Slack & Teams integration.
🚫Ad-Free — Uninterrupted experience.
Title
SeverityPoCActively ExploitedSourceDate
CVE-2026-91008
The Event Booking Manager for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including,...
MEDIUM??????????Wordfence5 days ago
CVE-2026-90923
The Autopay plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 5.0.0. This is due to a missing capability...
MEDIUM??????????Wordfence5 days ago
CVE-2026-90922
The Paid Member Subscriptions plugin for WordPress is vulnerable to Payment Bypass in all versions up to, and including, 3.0.8. This is due to a lack ...
MEDIUM??????????Wordfence5 days ago
CVE-2026-88904
The PuppyFW plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 0.4.4. This is due to insufficient restri...
MEDIUM??????????Wordfence5 days ago
CVE-2026-88795
The wpShopGermany IT-RECHT KANZLEI plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.3. This is due ...
CRITICAL??????????Wordfence5 days ago
CVE-2026-88792
The Dictionary plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 1.0. This is due to insufficien...
HIGH??????????Wordfence5 days ago
CVE-2026-87836
The Comments Import & Export plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions 2.1.11 to 2.5.3. This makes it p...
MEDIUM??????????Wordfence5 days ago
CVE-2026-87786
The Dewa Kirim plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 1.0.0. This is due to insuffici...
HIGH??????????Wordfence5 days ago
CVE-2026-86824
The Newsletter plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 9.3.7. This makes it possibl...
MEDIUM??????????Wordfence5 days ago
CVE-2026-86788
The HT Mega plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions 3.2.0 to 3.2.5. This is due to insufficient input saniti...
MEDIUM??????????Wordfence5 days ago
CVE-2026-86710
The Login with QR plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 1.0.0. This makes it possible for ...
CRITICAL??????????Wordfence5 days ago
CVE-2026-86709
The The Pressengine plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 1.0. This makes it possible for ...
CRITICAL??????????Wordfence5 days ago
CVE-2026-86707
The Private Feed Key plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 0.1. This makes it possible for...
CRITICAL??????????Wordfence5 days ago
CVE-2026-86446
The LearnPress plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions 4.4.3 to 4.4.6. This makes it possible for unauthe...
MEDIUM??????????Wordfence5 days ago
CVE-2026-85130
The WPLP Cookie Consent plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 4.4.3. This is due to ...
HIGH??????????Wordfence5 days ago
CVE-2026-85128
The Choose User Role at Registration for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, ...
CRITICAL??????????Wordfence5 days ago
CVE-2025-15697
The Dictionary plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 1.0. This is due to insuffic...
MEDIUM??????????Wordfence5 days ago
CVE-2026-25294
Transient DOS while parsing frame during channel usage.
HIGH??????????NVD5 days ago
CVE-2026-25290
Memory Corruption when validating large data buffers from external sources using addition to check buffer length.
HIGH??????????NVD5 days ago
CVE-2026-25284
Information Disclosure when a pointer is reused after being deallocated.
HIGH??????????NVD5 days ago
📧Email Delivery — Threat intel straight to your inbox.
♾️Unlimited Vendors — Track your entire stack.
🚨All New CVEs — Be the first to know.
⚙️Custom EPSS — Filter noise, focus on risk.
💬Webhooks — Slack & Teams integration.
🚫Ad-Free — Uninterrupted experience.
📧Email Delivery — Threat intel straight to your inbox.
♾️Unlimited Vendors — Track your entire stack.
🚨All New CVEs — Be the first to know.
⚙️Custom EPSS — Filter noise, focus on risk.
💬Webhooks — Slack & Teams integration.
🚫Ad-Free — Uninterrupted experience.