Critical Alert 4 Active Exploits Detected Today

CVE-2026-93952 Arista VeloCloud Orchestrator Improper Input Validation Vulnerability →
CVE-2026-94127 F5 BIG-IP APM Heap-based Buffer Overflow Vulnerability →
CVE-2026-93616 Check Point Multiple Products Path Traversal Vulnerability →
CVE-2026-85102 Check Point Multiple Products Improper Certificate Validation Vulnerability →
Powered by CVE Watchtower
×

CVE Watchtower

🔔 Premium Features
🔍 Filter Threats
📧Email Delivery — Threat intel straight to your inbox.
♾️Unlimited Vendors — Track your entire stack.
🚨All New CVEs — Be the first to know.
⚙️Custom EPSS — Filter noise, focus on risk.
💬Webhooks — Slack & Teams integration.
🚫Ad-Free — Uninterrupted experience.
📧Email Delivery — Threat intel straight to your inbox.
♾️Unlimited Vendors — Track your entire stack.
🚨All New CVEs — Be the first to know.
⚙️Custom EPSS — Filter noise, focus on risk.
💬Webhooks — Slack & Teams integration.
🚫Ad-Free — Uninterrupted experience.
Title
SeverityPoCActively ExploitedSourceDate
CVE-2026-25283
Memory Corruption when copying unverified data from an external source exceeds the allocated buffer size.
HIGH??????????NVD5 days ago
CVE-2026-25282
Transient DOS when processing unverified data from a neighboring system causes out of bound memory access.
HIGH??????????NVD5 days ago
CVE-2026-25281
Transient DOS when processing large or numerous request buffers without sufficient memory allocation validation.
HIGH??????????NVD5 days ago
CVE-2026-25280
Memory corruption when processing escape handling flow with insufficient user buffer sizes.
HIGH??????????NVD5 days ago
CVE-2026-25278
Memory Corruption when processing I2C transfer requests due to a race condition between memory allocation and data copying.
HIGH??????????NVD5 days ago
CVE-2026-25275
Transient DOS when processing authentication frames with invalid FILS information element header lengths.
HIGH??????????NVD5 days ago
CVE-2026-25261
Memory corruption while processing rear sensor IOCTL calls.
MEDIUM??????????NVD5 days ago
CVE-2026-24081
Transient DOS when processing a channel map with insufficient used channels and adaptive frequency hopping is fully enabled.
HIGH??????????NVD5 days ago
CVE-2026-24075
Memory Corruption when multiple threads issue concurrent IOCTL requests to the device control handler due to improper synchronization and race conditi...
HIGH??????????NVD5 days ago
CVE-2026-24074
Memory Corruption when processing data with large offset and length values exceeds buffer limits during data copy operations.
HIGH??????????NVD5 days ago
CVE-2026-24073
Memory corruption when processing decode statistics due to insufficient validation of offset against structure size.
HIGH??????????NVD5 days ago
CVE-2025-59607
Memory Corruption when copying large input data exceeds normal allocation limits.
HIGH??????????NVD5 days ago
CVE-2026-87796
The Multi Uploader for Gravity Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.1.9 via the m...
CRITICAL??????????Wordfence5 days ago
CVE-2026-87935
The Paid Downloads plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 3.15 via the admin_request_handle...
HIGH??????????Wordfence5 days ago
CVE-2026-50604
A vulnerability has been identified in the Acer Agent Service component included with NitroSense and PredatorSense. The socket handshake process does ...
UNKNOWN??????????NVD5 days ago
CVE-2026-50603
A vulnerability has been identified in the Acer Agent Service component included with NitroSense and PredatorSense. The vulnerability is caused by the...
UNKNOWN??????????NVD5 days ago
CVE-2026-92839
Canva Desktop before v1.125.0 performed double decoding in the deeplink handler. A threat actor could cause the application to load arbitrary same-ori...
MEDIUM??????????NVD5 days ago
CVE-2026-86311
The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Shortcode Attri...
MEDIUM??????????Wordfence5 days ago
CVE-2026-89064
The All-in-One WP Migration and Backup plugin for WordPress is vulnerable to Insufficient Credential Protection in versions up to, and including, 7.11...
MEDIUM??????????Wordfence5 days ago
CVE-2026-92838
A DLL hijacking vulnerability exists in the GeoVision GV-Remote E-Map desktop application. The application loads one or more dynamic-link libraries ...
HIGH??????????NVD6 days ago
📧Email Delivery — Threat intel straight to your inbox.
♾️Unlimited Vendors — Track your entire stack.
🚨All New CVEs — Be the first to know.
⚙️Custom EPSS — Filter noise, focus on risk.
💬Webhooks — Slack & Teams integration.
🚫Ad-Free — Uninterrupted experience.
📧Email Delivery — Threat intel straight to your inbox.
♾️Unlimited Vendors — Track your entire stack.
🚨All New CVEs — Be the first to know.
⚙️Custom EPSS — Filter noise, focus on risk.
💬Webhooks — Slack & Teams integration.
🚫Ad-Free — Uninterrupted experience.