CVE Watchtower

🔔 Premium Features
🔍 Filter Threats
📧Email Delivery — Threat intel straight to your inbox.
♾️Unlimited Vendors — Track your entire stack.
🚨All New CVEs — Be the first to know.
⚙️Custom EPSS — Filter noise, focus on risk.
💬Webhooks — Slack & Teams integration.
🚫Ad-Free — Uninterrupted experience.
📧Email Delivery — Threat intel straight to your inbox.
♾️Unlimited Vendors — Track your entire stack.
🚨All New CVEs — Be the first to know.
⚙️Custom EPSS — Filter noise, focus on risk.
💬Webhooks — Slack & Teams integration.
🚫Ad-Free — Uninterrupted experience.
Title
SeverityPoCActively ExploitedSourceDate
CVE-2026-54521
FairEmail is a fully featured, open source, privacy-friendly email app for Android. Prior to 1.2319, the ActivityAMP AMP message renderer in app/src/m...
MEDIUM??????????NVD4 days ago
CVE-2026-50277
dd-trace-cpp is the Datadog distributed tracing library for C++. Prior to 2.1.0, dd-trace-cpp parses incoming W3C baggage headers without enforcing DD...
HIGH??????????NVD4 days ago
CVE-2026-54501
Browsertrix is a high-fidelity, browser-based crawling service for web archiving that can be self-hosted or used through Webrecorder's hosted ins...
UNKNOWN??????????NVD4 days ago
CVE-2026-54237
Wavelog is web-based amateur radio logging software. From 1.8 until 2.4.2, Wavelog exposes /install/ajax.php and /install/includes/interface_assets/tr...
CRITICAL??????????NVD4 days ago
CVE-2026-45143
Chamilo LMS is an open-source learning management system. From 2.0.0 through at least 2.1.0, Chamilo LMS stores private Message.content without server...
CRITICAL??????????NVD4 days ago
CVE-2026-54460
OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to 1.1.1, POST /api/auth/passke...
CRITICAL??????????NVD4 days ago
CVE-2026-50022
Metacat is data repository software that helps researchers preserve, share, and discover data. Prior to 3.4.2, MetacatSolrIndex.query forwards the cli...
MEDIUM??????????NVD4 days ago
CVE-2026-50275
The Datadog PHP Tracer provides application performance monitoring and distributed tracing for PHP. Prior to 1.19.2, ddtrace_deserialize_baggage in ex...
HIGH??????????NVD4 days ago
CVE-2026-54918
NetBox Device Type Library is a collection of community-sourced device type definitions for import into NetBox. In the affected repository revisions, ...
MEDIUM??????????NVD4 days ago
CVE-2026-54916
NetBox Device Type Library is a collection of community-sourced device type definitions for import into NetBox. The absence of tests/init.py and the l...
HIGH??????????NVD4 days ago
CVE-2026-57846
No description available
UNKNOWN??????????NVD4 days ago
CVE-2026-54752
NetBox Device Type Library is a collection of community-sourced device type definitions for import into NetBox. The validation test harness can deseri...
CRITICAL??????????NVD4 days ago
CVE-2026-54594
OmniBlocks is a monorepo for the OmniBlocks project. Prior to the June 6, 2026 workflow remediation, .github/workflows/disc.yml runs for the issues op...
MEDIUM??????????NVD4 days ago
CVE-2026-54692
SAIL is a cross-platform library for loading and saving images with support for animation, metadata, and ICC profiles. Prior to 1.0.0, sail_codec_load...
HIGH??????????NVD4 days ago
CVE-2026-54627
SAIL is a cross-platform library for loading and saving images with support for animation, metadata, and ICC profiles. In 0.9.10 and earlier, psd_priv...
CRITICAL??????????NVD4 days ago
CVE-2026-54626
SAIL is a cross-platform library for loading and saving images with support for animation, metadata, and ICC profiles. In 0.9.10 and earlier, the TGA_...
CRITICAL??????????NVD4 days ago
CVE-2026-54618
Obsidian Web MCP is a secure remote MCP server for Obsidian vaults. Prior to 0.2.0, /oauth/authorize issues an authorization code without a login, con...
CRITICAL??????????NVD4 days ago
CVE-2026-54716
Valhalla is an open source routing engine and accompanying libraries for use with OpenStreetMap data. In 3.7.0 and earlier, a POST request to /sources...
HIGH??????????NVD4 days ago
CVE-2026-92757
Applications built on MongoDB Entity Framework Core Provider which place a database name in the connection string may inadvertently disable field leve...
MEDIUM??????????NVD4 days ago
CVE-2026-93337
NetworkManager-l2tp contains an improper input validation vulnerability that allows local users with VPN connection creation permissions to inject arb...
HIGH??????????NVD4 days ago
📧Email Delivery — Threat intel straight to your inbox.
♾️Unlimited Vendors — Track your entire stack.
🚨All New CVEs — Be the first to know.
⚙️Custom EPSS — Filter noise, focus on risk.
💬Webhooks — Slack & Teams integration.
🚫Ad-Free — Uninterrupted experience.
📧Email Delivery — Threat intel straight to your inbox.
♾️Unlimited Vendors — Track your entire stack.
🚨All New CVEs — Be the first to know.
⚙️Custom EPSS — Filter noise, focus on risk.
💬Webhooks — Slack & Teams integration.
🚫Ad-Free — Uninterrupted experience.