Critical Alert 4 Active Exploits Detected Today

CVE-2026-93952 Arista VeloCloud Orchestrator Improper Input Validation Vulnerability →
CVE-2026-94127 F5 BIG-IP APM Heap-based Buffer Overflow Vulnerability →
CVE-2026-93616 Check Point Multiple Products Path Traversal Vulnerability →
CVE-2026-85102 Check Point Multiple Products Improper Certificate Validation Vulnerability →
Powered by CVE Watchtower
×

CVE Watchtower

🔔 Premium Features
🔍 Filter Threats
📧Email Delivery — Threat intel straight to your inbox.
♾️Unlimited Vendors — Track your entire stack.
🚨All New CVEs — Be the first to know.
⚙️Custom EPSS — Filter noise, focus on risk.
💬Webhooks — Slack & Teams integration.
🚫Ad-Free — Uninterrupted experience.
📧Email Delivery — Threat intel straight to your inbox.
♾️Unlimited Vendors — Track your entire stack.
🚨All New CVEs — Be the first to know.
⚙️Custom EPSS — Filter noise, focus on risk.
💬Webhooks — Slack & Teams integration.
🚫Ad-Free — Uninterrupted experience.
Title
SeverityPoCActively ExploitedSourceDate
CVE-2026-87796
The Multi Uploader for Gravity Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.1.9 via the m...
CRITICAL??????????Wordfence5 days ago
CVE-2026-87935
The Paid Downloads plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 3.15 via the admin_request_handle...
HIGH??????????Wordfence5 days ago
CVE-2026-50604
A vulnerability has been identified in the Acer Agent Service component included with NitroSense and PredatorSense. The socket handshake process does ...
UNKNOWN??????????NVD5 days ago
CVE-2026-50603
A vulnerability has been identified in the Acer Agent Service component included with NitroSense and PredatorSense. The vulnerability is caused by the...
UNKNOWN??????????NVD5 days ago
CVE-2026-92839
Canva Desktop before v1.125.0 performed double decoding in the deeplink handler. A threat actor could cause the application to load arbitrary same-ori...
MEDIUM??????????NVD5 days ago
CVE-2026-86311
The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Shortcode Attri...
MEDIUM??????????Wordfence5 days ago
CVE-2026-89064
The All-in-One WP Migration and Backup plugin for WordPress is vulnerable to Insufficient Credential Protection in versions up to, and including, 7.11...
MEDIUM??????????Wordfence6 days ago
CVE-2026-92838
A DLL hijacking vulnerability exists in the GeoVision GV-Remote E-Map desktop application. The application loads one or more dynamic-link libraries ...
HIGH??????????NVD6 days ago
CVE-2026-81546
The Affinity by Canva application before 3.3.0 (September 2026 release) did not perform adequate bounds checking when parsing Affinity document files ...
HIGH??????????NVD6 days ago
WORDFENCE-dc1ae2c7-1eff-4976-8f88-f0b97a5cf323
WordPress Core is vulnerable to Missing Authorization via the wp_ajax_activate_plugin() AJAX action in various versions up to, and including, 7.1 due ...
LOW??????????Wordfence6 days ago
WORDFENCE-c41aadb1-e1a6-4bda-ac94-c461c320e78f
WordPress Core's HTML API WP_HTML_Tag_Processor::set_modifiable_text() (since 6.7.0) used an incomplete comment-closer guard (/--!?>/) that mi...
LOW??????????Wordfence6 days ago
WORDFENCE-c34ef5e3-afcd-4686-861f-5e382812233a
WordPress Core's theme installer (theme.js RunInstaller) passed the 'theme' slug from theme-install.php?theme=<slug> into a jQuer...
MEDIUM??????????Wordfence6 days ago
WORDFENCE-b54af5b0-d79a-4fb2-965f-d3ff4956dc5a
WordPress Core is vulnerable to Information Exposure via the attachment_submitbox_metadata() function in various versions up to, and including, 7.1 du...
MEDIUM??????????Wordfence6 days ago
WORDFENCE-adc90b32-f973-4c8e-b419-0614d4642b7f
WordPress Core is vulnerable to Insecure Direct Object Reference via the _wp_translate_postdata() function in various versions up to, and including, 7...
MEDIUM??????????Wordfence6 days ago
WORDFENCE-8b8d4431-ac72-45a2-b4a1-19690946d0ee
WordPress Core is vulnerable to Missing Authorization via the REST comments controller update_item_permissions_check() in various versions up to, and ...
MEDIUM??????????Wordfence6 days ago
WORDFENCE-83597e50-1992-4171-b24e-b14f55be6e4c
WordPress Core is vulnerable to Information Exposure via the wp_ajax_sample_permalink() and wp_ajax_get_permalink() AJAX actions in various versions u...
MEDIUM??????????Wordfence6 days ago
WORDFENCE-64453a11-e0dd-40f8-99c3-f05ef640b42b
WordPress Core is vulnerable to Path Traversal via the _get_block_template_file() function used by the REST templates controller (/wp/v2/templates/<...
MEDIUM??????????Wordfence6 days ago
WORDFENCE-3d59700b-3540-464c-bd27-23bb71f9b082
WordPress Core is vulnerable to Stored Cross-Site Scripting via the custom header 'header_image_data' theme mod in various versions up to, a...
MEDIUM??????????Wordfence6 days ago
WORDFENCE-28747e2e-9012-470c-a891-0fe97fd1ddba
WordPress Core is vulnerable to an authorization bypass via the XML-RPC _insert_post() handler in various versions up to, and including, 7.1 due to in...
MEDIUM??????????Wordfence6 days ago
WORDFENCE-1984abee-a74c-48d7-874f-c4421243e5e5
WordPress Core is vulnerable to Stored Cross-Site Scripting via the wpautop() function in various versions up to, and including, 7.1 due to a paragrap...
HIGH??????????Wordfence6 days ago
📧Email Delivery — Threat intel straight to your inbox.
♾️Unlimited Vendors — Track your entire stack.
🚨All New CVEs — Be the first to know.
⚙️Custom EPSS — Filter noise, focus on risk.
💬Webhooks — Slack & Teams integration.
🚫Ad-Free — Uninterrupted experience.
📧Email Delivery — Threat intel straight to your inbox.
♾️Unlimited Vendors — Track your entire stack.
🚨All New CVEs — Be the first to know.
⚙️Custom EPSS — Filter noise, focus on risk.
💬Webhooks — Slack & Teams integration.
🚫Ad-Free — Uninterrupted experience.