Critical Alert 1 Active Exploit Detected Today

CVE-2026-35273 Oracle PeopleSoft Enterprise PeopleTools Missing Authentication for Critical Function Vulnerability →
Powered by CVE Watchtower
×

CVE Watchtower

Advanced Threat Data Export

Filter and download the raw CVE repository (CSV/JSON) for SIEM integration and internal reporting.

Data export is locked. Upgrade your package to enable filtering and downloading.

πŸ”” Premium Features
πŸ” Filter Threats
Title
SeverityPoCActively ExploitedSourceDate
CVE-2026-41974
Permission control vulnerability in service notifications.Β Impact: Successful exploitation of this vulnerability may affect availability.
LOW??????????NVD3 days ago
CVE-2026-41973
Permission control vulnerability in calls.Β Impact: Successful exploitation of this vulnerability may affect availability.
MEDIUM??????????NVD3 days ago
CVE-2026-41972
Path traversal vulnerability in the SMS app.Β Impact: Successful exploitation of this vulnerability may affect availability.
MEDIUM??????????NVD3 days ago
CVE-2026-44083
An authorization bypass through user-controlled key vulnerability has been reported to affect QuMagie. The remote attackers can then exploit the vulne...
UNKNOWN??????????NVD3 days ago
CVE-2025-62858
A buffer overflow vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator accoun...
UNKNOWN??????????NVD3 days ago
CVE-2026-8981
The Custom Block Builder WordPress plugin before 4.3.0 does not consistently check the unfiltered_html capability across all paths that write to its ...
LOW??????????NVD3 days ago
CVE-2026-5067
A remote, unauthenticated attacker can trigger memory corruption in Zephyr's HTTP server WebSocket upgrade path by sending a crafted Sec-WebSocke...
CRITICAL??????????NVD3 days ago
CVE-2026-4986
The WPForms WordPress plugin before 1.10.0.5 does not verify the authenticity of incoming PayPal webhook events before processing them, allowing unau...
MEDIUM??????????NVD3 days ago
CVE-2026-41539
A cross-site scripting (XSS) vulnerability has been reported to affect several QNAP operating system versions. The remote attackers can then exploit t...
UNKNOWN??????????NVD3 days ago
CVE-2026-9662
The Recover Exit For WooCommerce plugin for WordPress is vulnerable to Local File Inclusion in all versions up to and including 1.0.3. This is due to ...
HIGH??????????NVD3 days ago
CVE-2026-9185
The 6Storage Rentals plugin for WordPress is vulnerable to Authorization Bypass Through User-Controlled Key in all versions up to and including 2.22.0...
HIGH??????????NVD3 days ago
CVE-2026-8977
The WP GDPR Cookie Consent plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ninja_gdpr_ajax_actions' AJAX action i...
MEDIUM??????????NVD3 days ago
CVE-2026-8940
The WP Meta Sort Posts plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.9. This is due to miss...
MEDIUM??????????NVD3 days ago
CVE-2026-8910
The WP Emoticon Rating plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.1. This is due to mi...
MEDIUM??????????NVD3 days ago
CVE-2026-8909
The WpMobi plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.0.3. This is due to missing or inc...
MEDIUM??????????NVD3 days ago
CVE-2026-8907
The WP-Ultimate-Map plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1. This is due to missing non...
MEDIUM??????????NVD3 days ago
CVE-2026-8904
The FastPicker, an order picker and order management system (oms) for WooCommerce on steroids plugin for WordPress is vulnerable to Cross-Site Request...
MEDIUM??????????NVD3 days ago
CVE-2026-8902
The AJAX Report Comments plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.0.4. This is due to ...
MEDIUM??????????NVD3 days ago
CVE-2026-8895
The kk blog card plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'blog-card' shortcode in all versio...
MEDIUM??????????NVD3 days ago
CVE-2026-8883
The Global Body Mass Index Calculator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'gbmicalc' shortcode in vers...
MEDIUM??????????NVD3 days ago