Critical Alert 3 Active Exploits Detected Today

CVE-2025-39964 Linux Kernel Race Condition Vulnerability →
CVE-2026-53266 Linux Kernel Out-of-Bounds Write Vulnerability →
CVE-2025-39682 Linux Kernel Improper Check for Unusual or Exceptional Conditions Vulnerability →
Powered by CVE Watchtower
×

CVE Watchtower

🔔 Premium Features
(Level 1+ required)
(Level 2+ required)
(Level 3 required)
🔍 Filter Threats
Title
SeverityProof of Concept
Actively Exploited
SourceDate
CVE-2026-93371
A security vulnerability has been detected in marcopiovanello yt-dlp-web-ui up to v4. This issue affects the function NewGenericDownload of the file s...
HIGH??????????NVD2 days ago
CVE-2026-93331
A vulnerability was identified in GPAC 26.08-DEV. This vulnerability affects the function gf_rtp_parse_ttxt of the file src/ietf/rtp_depacketizer.c of...
HIGH??????????NVD2 days ago
CVE-2026-93314
A vulnerability was determined in Freedesktop Poppler 26.07.0. This affects the function FoFiTrueType::mapCodeToGID of the file fofi/FoFiTrueType.cc. ...
MEDIUM??????????NVD2 days ago
CVE-2026-82985
The Photos app's filter-based "smart albums" build their file listing using the search configuration (photosSourceFolders) of the user ...
MEDIUM??????????NVD2 days ago
CVE-2026-82982
The Approval app's approve/reject endpoint is meant to require the file's current etag as a freshness check, preventing an approver from app...
MEDIUM??????????NVD2 days ago
CVE-2026-82980
Any authenticated user can lock or unlock files they do not own by targeting absolute WebDAV paths of other users. The DAV plugin resolves files from ...
MEDIUM??????????NVD2 days ago
CVE-2026-77170
The Deck config API allows authenticated users to set board-scoped configuration keys for arbitrary board IDs without validating whether the user owns...
MEDIUM??????????NVD2 days ago
CVE-2026-77169
A vulnerability in the team folders (formerly group folders) app when used in combination with the workspace app allowed API/REST-only delegated admin...
MEDIUM??????????NVD2 days ago
CVE-2026-77164
Circles' remote-instance signature verification fetches the attacker-supplied keyId URL before trust in the remote instance is established, and e...
MEDIUM??????????NVD2 days ago
CVE-2026-68493
After guessing a 62^15 complex unique identifier, a malicious logged in user was able to retrieve a list of memberships for a circle they are not a me...
LOW??????????NVD2 days ago
CVE-2026-93456
django-page-cms through 2.0.13 exempts five admin mutation views from CSRF protection in pages/admin/views.py, allowing attackers to forge requests th...
HIGH??????????NVD2 days ago
CVE-2026-93455
django-page-cms through 2.0.13 fails to properly validate page permissions in admin helper views, allowing any staff account to read arbitrary page co...
MEDIUM??????????NVD2 days ago
CVE-2026-93313
A vulnerability was found in Freedesktop Poppler 26.07.0. The impacted element is the function JBIG2Stream::readCodeTableSeg of the file poppler/JBIG2...
MEDIUM??????????NVD2 days ago
CVE-2026-93312
A flaw has been found in Freedesktop Poppler 26.07.0. Impacted is the function JBIG2Stream::rewind of the file poppler/JBIG2Stream.cc. This manipulati...
MEDIUM??????????NVD2 days ago
CVE-2026-93311
A vulnerability was detected in Freedesktop Poppler 26.07.0. This issue affects the function SampledFunction::SampledFunction of the file poppler/Func...
MEDIUM??????????NVD2 days ago
CVE-2026-79954
NASA CryptoLib 1.5.0 contains an authentication downgrade vulnerability in the Telecommand (TC) receive path. The receiver selects the Security Associ...
HIGH??????????NVD2 days ago
CVE-2026-93310
A vulnerability was identified in O-RAN-SC SMO OAM 2025-06-10. This affects an unknown part of the component VES Collector. The manipulation leads to ...
MEDIUM??????????NVD2 days ago
CVE-2026-79294
Cross Site Scripting vulnerability in Moonshot AI Kimi version as of 2026-07-18 allows a remote attacker to execute arbitrary code via the HTML artifa...
UNKNOWN??????????NVD2 days ago
CVE-2026-88623
NUUO Network Video Recorder 2.0.0 is vulnerable to arbitrary file read. In up.php, the url parameter submitted by the user via POST is received, and f...
UNKNOWN??????????NVD2 days ago
CVE-2026-88622
NUUO Network Video Recorder 2.0.0 is vulnerable to Command Injection in handle_import_privilege.php.
UNKNOWN??????????NVD2 days ago