CVE Watchtower

🔔 Premium Features
(Level 1+ required)
(Level 2+ required)
(Level 3 required)
🔍 Filter Threats
📧Email Delivery — Threat intel straight to your inbox.
♾️Unlimited Vendors — Track your entire stack.
🚨All New CVEs — Be the first to know.
⚙️Custom EPSS — Filter noise, focus on risk.
💬Webhooks — Slack & Teams integration.
🚫Ad-Free — Uninterrupted experience.
📧Email Delivery — Threat intel straight to your inbox.
♾️Unlimited Vendors — Track your entire stack.
🚨All New CVEs — Be the first to know.
⚙️Custom EPSS — Filter noise, focus on risk.
💬Webhooks — Slack & Teams integration.
🚫Ad-Free — Uninterrupted experience.
Title
SeverityProof of Concept
Actively Exploited
SourceDate
CVE-2026-93337
NetworkManager-l2tp contains an improper input validation vulnerability that allows local users with VPN connection creation permissions to inject arb...
HIGH??????????NVD2 days ago
CVE-2026-92758
If logging mode is set to DEBUG or a malformed MongoDB connection string is used, application logs may collect sensitive information (if in use) such ...
MEDIUM??????????NVD2 days ago
CVE-2026-92993
A vulnerability was detected in Dromara mayfly-go up to 1.11.5. The impacted element is the function RunMachineScript of the file server/internal/mach...
MEDIUM??????????NVD2 days ago
CVE-2026-92943
Improper validation of certificate with host mismatch in the MQTT client TLS connection layer in AWS IoT Device SDK for Python 1.5.3 through 1.6.0 on ...
HIGH??????????NVD2 days ago
CVE-2026-92756
Applications built on MongoDB Entity Framework Core Provider which combine independent encryption settings and this provider's encryption setting...
MEDIUM??????????NVD2 days ago
CVE-2026-68537
`fulgur` converts untrusted HTML/CSS into PDF, commonly on a server that processes input supplied by many tenants. In versions prior to 0.19.0, a body...
HIGH??????????NVD2 days ago
CVE-2026-68523
`fulgur` converts untrusted HTML/CSS into PDF, commonly on a server that processes input supplied by many tenants. In versions prior to 0.19.0, a body...
HIGH??????????NVD2 days ago
CVE-2026-90997
A flaw was found in Keycloak. When deployed in stateless mode with MySQL or MariaDB, a mismatch in row-count semantics between the database driver and...
HIGH??????????NVD2 days ago
CVE-2026-19477
There is stack-based buffer overflow vulnerability recently discovered in MCC Universal Library for Linux (uldaq).  This may result in information di...
HIGH??????????NVD2 days ago
CVE-2026-92230
Apache Karaf's XmlUtils cached XML parser/transformer factories in static ThreadLocal fields on long-lived container threads. Because a ThreadLoc...
UNKNOWN??????????NVD2 days ago
CVE-2026-54253
TS3 Manager is modern web interface for maintaining Teamspeak3 servers. Prior to 2.2.6, the /api/download handler in packages/server/routes/api.js pas...
HIGH??????????NVD2 days ago
CVE-2026-54524
Frappe HR is an open-source human resources management solution (HRMS). Prior to 16.7.0, an authenticated user with the HR User role can inject SQL th...
UNKNOWN??????????NVD2 days ago
CVE-2026-52852
Traccar is an open source GPS tracking system. Prior to 6.14.0, an authenticated user with permission to manage groups and request reports can create ...
MEDIUM??????????NVD2 days ago
CVE-2026-52851
Traccar is an open source GPS tracking system. Prior to 6.14.0, an authenticated, non-readonly user with access to an object usable in a permission pa...
HIGH??????????NVD2 days ago
CVE-2026-92992
A security vulnerability has been detected in Dromara mayfly-go up to 1.11.5. The affected element is an unknown function of the file server/internal/...
MEDIUM??????????NVD2 days ago
CVE-2026-54649
punchin-email is a Cloudflare Email Worker that provides two-way role aliases while relaying mail to a private inbox. Prior to 1.5.0, handleInbound de...
UNKNOWN??????????NVD2 days ago
CVE-2026-54571
ESPAsyncWebServer is an asynchronous HTTP and WebSocket server library for ESP32, ESP8266, RP2040 and RP2350. Prior to 3.11.1, the multipart/form-data...
UNKNOWN??????????NVD2 days ago
CVE-2026-54239
Faust.js is a headless WordPress toolkit. Prior to 1.8.11, the FaustWP WordPress plugin authenticates only the ciphertext in its token envelope and ex...
HIGH??????????NVD2 days ago
CVE-2026-52727
lxc-ci contains continuous integration and image-build scripts for LXC. Prior to the 2026-05-28 Arch Linux image publication, images built from images...
HIGH??????????NVD2 days ago
CVE-2026-92927
A vulnerability was found in SourceCodester Drug Recommendation System 1.0. This issue affects some unknown processing of the file /db/drug_recommendo...
MEDIUM??????????NVD2 days ago
📧Email Delivery — Threat intel straight to your inbox.
♾️Unlimited Vendors — Track your entire stack.
🚨All New CVEs — Be the first to know.
⚙️Custom EPSS — Filter noise, focus on risk.
💬Webhooks — Slack & Teams integration.
🚫Ad-Free — Uninterrupted experience.
📧Email Delivery — Threat intel straight to your inbox.
♾️Unlimited Vendors — Track your entire stack.
🚨All New CVEs — Be the first to know.
⚙️Custom EPSS — Filter noise, focus on risk.
💬Webhooks — Slack & Teams integration.
🚫Ad-Free — Uninterrupted experience.