Critical Alert 1 Active Exploit Detected Today

CVE-2026-35273 Oracle PeopleSoft Enterprise PeopleTools Missing Authentication for Critical Function Vulnerability →
Powered by CVE Watchtower
×

CVE Watchtower

Advanced Threat Data Export

Filter and download the raw CVE repository (CSV/JSON) for SIEM integration and internal reporting.

Data export is locked. Upgrade your package to enable filtering and downloading.

πŸ”” Premium Features
πŸ” Filter Threats
Title
SeverityPoCActively ExploitedSourceDate
CVE-2026-11572
Versions of the package degit before 2.8.6, from 3.0.0 and before 3.3.1 are vulnerable to Command Injection due to improper sanitisation of user input...
HIGH??????????NVD3 days ago
CVE-2026-26236
A missing authorization vulnerability has been reported to affect QuMagie. The remote attackers can then exploit the vulnerability to access unauthori...
UNKNOWN??????????NVD3 days ago
CVE-2026-7556
The FV Flowplayer Video Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the comment text in all versions up to, and inclu...
HIGH??????????NVD3 days ago
CVE-2026-5714
The Enable Media Replace plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the β€˜location_dir’ parameter in all versions up to,...
MEDIUM??????????NVD3 days ago
CVE-2026-11623
A security vulnerability has been detected in tmux up to 3.6a. Affected is the function image_free of the file image.c. Such manipulation leads to use...
MEDIUM??????????NVD3 days ago
CVE-2026-11621
A weakness has been identified in Dcat-Admin up to 2.2.3-beta. This impacts the function editorMDUpload of the file /admin/dcat-api/editor-md/upload o...
MEDIUM??????????NVD3 days ago
CVE-2026-11620
A security flaw has been discovered in TOTOLINK EX200 4.0.3c.7646. This affects an unknown function of the file /etc/vsftpd.conf of the component vsft...
MEDIUM??????????NVD3 days ago
CVE-2026-11619
A vulnerability was identified in Dolibarr ERP CRM up to 23.0.2. The impacted element is an unknown function of the file htdocs/core/filemanagerdol/co...
MEDIUM??????????NVD3 days ago
CVE-2026-10862
The Accordions plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Accordion body field in all versions up to, and including, 2....
MEDIUM??????????NVD3 days ago
CVE-2026-11618
A vulnerability was determined in DTStack Taier up to 1.4.0. The affected element is the function preHandle of the file taier-data-develop/src/main/ja...
HIGH??????????NVD3 days ago
???-????-????
??????????????????????????????????
??????????????????????????????????
HIGH??????????SA4 days ago
???-????-????
??????????????????????????????????
??????????????????????????????????
HIGH??????????SA4 days ago
CVE-2026-8795
A YAML injection vulnerability exists in the Windows.Collectors.Remapping artifact of Rapid7 Velociraptor before version 0.76.6. The hostname field in...
HIGH??????????NVD4 days ago
CVE-2026-44757
SAP Wily Introscope Enterprise Manager allows an unauthenticated attacker to craft a specially crafted URL. Under certain conditions, when accessed by...
MEDIUM??????????NVD4 days ago
CVE-2026-44755
SAP Business Objects Business Intelligence Platform does not sufficiently validate email sending parameters supplied by authenticated users, resulting...
MEDIUM??????????NVD4 days ago
CVE-2026-44754
The Remote Function Call (RFC) modules of the Operational Data Provisioning Data Replication API (ODP-RFC) are missing caller identification of permit...
MEDIUM??????????NVD4 days ago
CVE-2026-44751
Application server ABAP does not perform necessary authorization checks for an authenticated user allowing an attacker to execute a report generation ...
HIGH??????????NVD4 days ago
CVE-2026-44750
SAP MDG (Review Match Groups Application) does not perform the necessary authorization checks for authenticated users. This could allow a low-privileg...
MEDIUM??????????NVD4 days ago
CVE-2026-44748
SAP NetWeaver Application Server ABAP and ABAP Platform allows an authenticated attacker with normal privileges to obtain a valid signed message and s...
CRITICAL??????????NVD4 days ago
CVE-2026-44746
Due to a reflected cross-site scripting (XSS) vulnerability in SAP NetWeaver JAVA (JDBC Test Servlet), an unauthenticated attacker could craft a URL t...
MEDIUM??????????NVD4 days ago