Critical Alert 1 Active Exploit Detected Today

CVE-2026-10520 Ivanti Sentry OS Command Injection Vulnerability →
Powered by CVE Watchtower
×

CVE Watchtower

Advanced Threat Data Export

Filter and download the raw CVE repository (CSV/JSON) for SIEM integration and internal reporting.

Data export is locked. Upgrade your package to enable filtering and downloading.

🔔 Premium Features
🔍 Filter Threats
Title
SeverityPoCActively ExploitedSourceDate
CVE-2026-47352
Authenticated backend users were able to retrieve file metadata via several Backend API routes without proper permission checks, allowing access to fi...
UNKNOWN??????????NVD3 days ago
CVE-2026-47351
Backend users were able to insert arbitrary records and files into the TYPO3 clipboard without proper read permission checks, which allowed users to g...
UNKNOWN??????????NVD3 days ago
CVE-2026-47350
Backend users were able to move records to a different page without having edit permissions on the source page. This issue affects TYPO3 CMS versions ...
UNKNOWN??????????NVD3 days ago
CVE-2026-47349
Backend users with access to the Recycler module were able to restore soft-deleted records on pages or for tables they were not authorized to modify. ...
UNKNOWN??????????NVD3 days ago
CVE-2026-47348
Editors with access to create or modify page content were able to include HTML markup in page titles that were stored in the search index without sani...
UNKNOWN??????????NVD3 days ago
CVE-2026-47347
Applications that use GeneralUtility::sanitizeLocalUrl to allow only local URLs are vulnerable to open redirect attacks if the URL is used after it ha...
UNKNOWN??????????NVD3 days ago
CVE-2026-47346
Backend users with file write permissions were able to upload form definition files with mixed-case extensions (e.g., .FORM.YAML) to bypass the Form F...
UNKNOWN??????????NVD3 days ago
CVE-2026-47343
Non-privileged backend users with file mount access were able to perform write operations (move, delete, rename) on folders representing the root of a...
UNKNOWN??????????NVD3 days ago
CVE-2026-11607
Backend users with access to the Form Framework were able to use files not ending in .form.yaml as form definitions, which were processed without deny...
UNKNOWN??????????NVD3 days ago
CVE-2026-52902
A path traversal vulnerability was found in awxkit, the CLI tool for AWX. The YAML !include directive does not sanitize file paths, allowing an attack...
MEDIUM??????????NVD3 days ago
CVE-2026-4058
The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration plugin for WordPress is vulnerable to unau...
MEDIUM??????????NVD3 days ago
CVE-2025-10263
Arm C1-Ultra, C1-Premium, Neoverse V3 & V3AE, Neoverse V2, Neoverse V1, Neoverse-N2, Neoverse-N1, Cortex-X925, Cortex-X4, Cortex-X3, Cortex-X2, Co...
CRITICAL??????????NVD3 days ago
CVE-2026-41031
A Stored Cross-Site Scripting vulnerability in Vinna Process Monitor Version 4.0 Service Pack 1 (Build 63255) allows an authenticated remote attacker ...
HIGH??????????NVD3 days ago
CVE-2026-8677
The Prime Elementor Addons – Lightweight Elementor Widgets for Faster Pages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Wi...
MEDIUM??????????NVD3 days ago
CVE-2026-8599
The MailerPress – Email Marketing, Newsletter, Email Automation & WooCommerce Emails plugin for WordPress is vulnerable to Stored Cross-Site Scr...
MEDIUM??????????NVD3 days ago
CVE-2026-8365
The Blocksy theme for WordPress is vulnerable to PHP Object Injection leading to Remote Code Execution via the 'blocksy_meta' REST API field...
HIGH??????????NVD3 days ago
CVE-2026-7542
The Slider Revolution plugin for WordPress is vulnerable to Sensitive Information Disclosure in versions up to and including 7.0.10. This is due to th...
MEDIUM??????????NVD3 days ago
CVE-2026-6899
Check for certificate revocation only considers the first matching CRL and ignores other valid CRLs of the same CA in the CycloneCrypto cryptographic ...
MEDIUM??????????NVD3 days ago
CVE-2026-49818
The Apache Airflow Samba provider's `GCSToSambaOperator` joined GCS object names to the SMB destination path without a containment check, so an o...
MEDIUM??????????NVD3 days ago
CVE-2026-46315
In the Linux kernel, the following vulnerability has been resolved: io_uring/waitid: clear waitid info before copying it to userspace IORING_OP_WAIT...
UNKNOWN??????????NVD3 days ago