Critical Alert 4 Active Exploits Detected Today

CVE-2026-93952 Arista VeloCloud Orchestrator Improper Input Validation Vulnerability →
CVE-2026-94127 F5 BIG-IP APM Heap-based Buffer Overflow Vulnerability →
CVE-2026-93616 Check Point Multiple Products Path Traversal Vulnerability →
CVE-2026-85102 Check Point Multiple Products Improper Certificate Validation Vulnerability →
Powered by CVE Watchtower
×

CVE Watchtower

🔔 Premium Features
🔍 Filter Threats
📧Email Delivery — Threat intel straight to your inbox.
♾️Unlimited Vendors — Track your entire stack.
🚨All New CVEs — Be the first to know.
⚙️Custom EPSS — Filter noise, focus on risk.
💬Webhooks — Slack & Teams integration.
🚫Ad-Free — Uninterrupted experience.
📧Email Delivery — Threat intel straight to your inbox.
♾️Unlimited Vendors — Track your entire stack.
🚨All New CVEs — Be the first to know.
⚙️Custom EPSS — Filter noise, focus on risk.
💬Webhooks — Slack & Teams integration.
🚫Ad-Free — Uninterrupted experience.
Title
SeverityPoCActively ExploitedSourceDate
CVE-2026-92991
The Biggop Library is vulnerable to Cross-Site Scripting via the ‘display_id’ parameter from the Sigmative API in various versions due to insuffic...
MEDIUM??????????Wordfence5 days ago
CVE-2026-14855
The RT Mega Menu plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'css[left]' parameter in all versions up to, and ...
MEDIUM??????????Wordfence5 days ago
CVE-2026-15650
The RT Mega Menu – Mega Menu Builder for Elementor & Gutenberg plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'point...
MEDIUM??????????Wordfence5 days ago
CVE-2026-93468
The OAKlouds developed by HGiga has an Arbitrary File Read vulnerability. Unauthenticated remote attackers can exploit Relative Path Traversal to read...
HIGH??????????NVD5 days ago
CVE-2026-93467
The OAKlouds developed by HGiga has a Insecure Deserialization vulnerability. Unauthenticated remote attackers can execute arbitrary code on the serve...
CRITICAL??????????NVD5 days ago
CVE-2026-93371
A security vulnerability has been detected in marcopiovanello yt-dlp-web-ui up to v4. This issue affects the function NewGenericDownload of the file s...
HIGH??????????NVD5 days ago
CVE-2026-93331
A vulnerability was identified in GPAC 26.08-DEV. This vulnerability affects the function gf_rtp_parse_ttxt of the file src/ietf/rtp_depacketizer.c of...
HIGH??????????NVD5 days ago
CVE-2026-93314
A vulnerability was determined in Freedesktop Poppler 26.07.0. This affects the function FoFiTrueType::mapCodeToGID of the file fofi/FoFiTrueType.cc. ...
MEDIUM??????????NVD5 days ago
CVE-2026-82985
The Photos app's filter-based "smart albums" build their file listing using the search configuration (photosSourceFolders) of the user ...
MEDIUM??????????NVD5 days ago
CVE-2026-82982
The Approval app's approve/reject endpoint is meant to require the file's current etag as a freshness check, preventing an approver from app...
MEDIUM??????????NVD5 days ago
CVE-2026-82980
Any authenticated user can lock or unlock files they do not own by targeting absolute WebDAV paths of other users. The DAV plugin resolves files from ...
MEDIUM??????????NVD5 days ago
CVE-2026-77170
The Deck config API allows authenticated users to set board-scoped configuration keys for arbitrary board IDs without validating whether the user owns...
MEDIUM??????????NVD5 days ago
CVE-2026-77169
A vulnerability in the team folders (formerly group folders) app when used in combination with the workspace app allowed API/REST-only delegated admin...
MEDIUM??????????NVD5 days ago
CVE-2026-77164
Circles' remote-instance signature verification fetches the attacker-supplied keyId URL before trust in the remote instance is established, and e...
MEDIUM??????????NVD5 days ago
CVE-2026-68493
After guessing a 62^15 complex unique identifier, a malicious logged in user was able to retrieve a list of memberships for a circle they are not a me...
LOW??????????NVD5 days ago
CVE-2026-93456
django-page-cms through 2.0.13 exempts five admin mutation views from CSRF protection in pages/admin/views.py, allowing attackers to forge requests th...
HIGH??????????NVD5 days ago
CVE-2026-93455
django-page-cms through 2.0.13 fails to properly validate page permissions in admin helper views, allowing any staff account to read arbitrary page co...
MEDIUM??????????NVD5 days ago
CVE-2026-93313
A vulnerability was found in Freedesktop Poppler 26.07.0. The impacted element is the function JBIG2Stream::readCodeTableSeg of the file poppler/JBIG2...
MEDIUM??????????NVD5 days ago
CVE-2026-93312
A flaw has been found in Freedesktop Poppler 26.07.0. Impacted is the function JBIG2Stream::rewind of the file poppler/JBIG2Stream.cc. This manipulati...
MEDIUM??????????NVD5 days ago
CVE-2026-93311
A vulnerability was detected in Freedesktop Poppler 26.07.0. This issue affects the function SampledFunction::SampledFunction of the file poppler/Func...
MEDIUM??????????NVD5 days ago
📧Email Delivery — Threat intel straight to your inbox.
♾️Unlimited Vendors — Track your entire stack.
🚨All New CVEs — Be the first to know.
⚙️Custom EPSS — Filter noise, focus on risk.
💬Webhooks — Slack & Teams integration.
🚫Ad-Free — Uninterrupted experience.
📧Email Delivery — Threat intel straight to your inbox.
♾️Unlimited Vendors — Track your entire stack.
🚨All New CVEs — Be the first to know.
⚙️Custom EPSS — Filter noise, focus on risk.
💬Webhooks — Slack & Teams integration.
🚫Ad-Free — Uninterrupted experience.