Critical Alert 1 Active Exploit Detected Today

CVE-2026-7273 Zyxel GS1900 Series Switches Stack-Based Buffer Overflow Vulnerability →
Powered by CVE Watchtower
×

CVE Watchtower

🔔 Premium Features
🔍 Filter Threats
📧Email Delivery — Threat intel straight to your inbox.
♾️Unlimited Vendors — Track your entire stack.
🚨All New CVEs — Be the first to know.
⚙️Custom EPSS — Filter noise, focus on risk.
💬Webhooks — Slack & Teams integration.
🚫Ad-Free — Uninterrupted experience.
📧Email Delivery — Threat intel straight to your inbox.
♾️Unlimited Vendors — Track your entire stack.
🚨All New CVEs — Be the first to know.
⚙️Custom EPSS — Filter noise, focus on risk.
💬Webhooks — Slack & Teams integration.
🚫Ad-Free — Uninterrupted experience.
Title
SeverityPoCActively ExploitedSourceDate
CVE-2026-45143
Chamilo LMS is an open-source learning management system. From 2.0.0 through at least 2.1.0, Chamilo LMS stores private Message.content without server...
CRITICAL??????????NVD4 days ago
CVE-2026-54460
OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to 1.1.1, POST /api/auth/passke...
CRITICAL??????????NVD4 days ago
CVE-2026-50022
Metacat is data repository software that helps researchers preserve, share, and discover data. Prior to 3.4.2, MetacatSolrIndex.query forwards the cli...
MEDIUM??????????NVD4 days ago
CVE-2026-50275
The Datadog PHP Tracer provides application performance monitoring and distributed tracing for PHP. Prior to 1.19.2, ddtrace_deserialize_baggage in ex...
HIGH??????????NVD4 days ago
CVE-2026-54918
NetBox Device Type Library is a collection of community-sourced device type definitions for import into NetBox. In the affected repository revisions, ...
MEDIUM??????????NVD4 days ago
CVE-2026-54916
NetBox Device Type Library is a collection of community-sourced device type definitions for import into NetBox. The absence of tests/init.py and the l...
HIGH??????????NVD4 days ago
CVE-2026-57846
No description available
UNKNOWN??????????NVD4 days ago
CVE-2026-54594
OmniBlocks is a monorepo for the OmniBlocks project. Prior to the June 6, 2026 workflow remediation, .github/workflows/disc.yml runs for the issues op...
MEDIUM??????????NVD4 days ago
CVE-2026-54627
SAIL is a cross-platform library for loading and saving images with support for animation, metadata, and ICC profiles. In 0.9.10 and earlier, psd_priv...
CRITICAL??????????NVD4 days ago
CVE-2026-54626
SAIL is a cross-platform library for loading and saving images with support for animation, metadata, and ICC profiles. In 0.9.10 and earlier, the TGA_...
CRITICAL??????????NVD4 days ago
CVE-2026-54618
Obsidian Web MCP is a secure remote MCP server for Obsidian vaults. Prior to 0.2.0, /oauth/authorize issues an authorization code without a login, con...
CRITICAL??????????NVD4 days ago
CVE-2026-54716
Valhalla is an open source routing engine and accompanying libraries for use with OpenStreetMap data. In 3.7.0 and earlier, a POST request to /sources...
HIGH??????????NVD4 days ago
CVE-2026-92757
Applications built on MongoDB Entity Framework Core Provider which place a database name in the connection string may inadvertently disable field leve...
MEDIUM??????????NVD4 days ago
CVE-2026-93337
NetworkManager-l2tp contains an improper input validation vulnerability that allows local users with VPN connection creation permissions to inject arb...
HIGH??????????NVD4 days ago
CVE-2026-90997
A flaw was found in Keycloak. When deployed in stateless mode with MySQL or MariaDB, a mismatch in row-count semantics between the database driver and...
HIGH??????????NVD4 days ago
CVE-2026-52852
Traccar is an open source GPS tracking system. Prior to 6.14.0, an authenticated user with permission to manage groups and request reports can create ...
MEDIUM??????????NVD4 days ago
CVE-2026-92758
If logging mode is set to DEBUG or a malformed MongoDB connection string is used, application logs may collect sensitive information (if in use) such ...
MEDIUM??????????NVD4 days ago
CVE-2026-92993
A vulnerability was detected in Dromara mayfly-go up to 1.11.5. The impacted element is the function RunMachineScript of the file server/internal/mach...
MEDIUM??????????NVD4 days ago
CVE-2026-92943
Improper validation of certificate with host mismatch in the MQTT client TLS connection layer in AWS IoT Device SDK for Python 1.5.3 through 1.6.0 on ...
HIGH??????????NVD4 days ago
CVE-2026-92756
Applications built on MongoDB Entity Framework Core Provider which combine independent encryption settings and this provider's encryption setting...
MEDIUM??????????NVD4 days ago
📧Email Delivery — Threat intel straight to your inbox.
♾️Unlimited Vendors — Track your entire stack.
🚨All New CVEs — Be the first to know.
⚙️Custom EPSS — Filter noise, focus on risk.
💬Webhooks — Slack & Teams integration.
🚫Ad-Free — Uninterrupted experience.
📧Email Delivery — Threat intel straight to your inbox.
♾️Unlimited Vendors — Track your entire stack.
🚨All New CVEs — Be the first to know.
⚙️Custom EPSS — Filter noise, focus on risk.
💬Webhooks — Slack & Teams integration.
🚫Ad-Free — Uninterrupted experience.