Critical Alert 4 Active Exploits Detected Today

CVE-2026-19490 Citrix NetScaler Authentication Bypass Using an Alternate Path or Channel Vulnerability →
CVE-2025-25249 Fortinet Multiple Products Heap-based Buffer Overflow Vulnerability →
CVE-2026-87491 Google Chromium V8 Out of Bounds Write Vulnerability →
CVE-2026-20079 Cisco Firewall Management Center Authentication Bypass Using an Alternate Path or Channel Vulnerability →
Powered by CVE Watchtower
×

CVE Watchtower

Advanced Threat Data Export

Filter and download the raw CVE repository (CSV/JSON) for SIEM integration and internal reporting.

Data export is locked. Upgrade your package to enable filtering and downloading.

🔔 Premium Features
🔍 Filter Threats
Title
SeverityPoCActively ExploitedSourceDate
???-????-????
??????????????????????????????????
??????????????????????????????????
CRITICAL??????????SA8 hours ago
???-????-????
??????????????????????????????????
??????????????????????????????????
HIGH??????????SA9 hours ago
???-????-????
??????????????????????????????????
??????????????????????????????????
MEDIUM??????????SA1 day ago
???-????-????
??????????????????????????????????
??????????????????????????????????
CRITICAL??????????SA1 day ago
???-????-????
??????????????????????????????????
??????????????????????????????????
CRITICAL??????????SA2 days ago
CVE-2026-59185
## Summary identrail's GitHub App connection-completion endpoint binds a fully client-supplied `installation_id` to the caller's workspace ...
HIGH??????????NVD52 minutes ago
CVE-2026-59179
## Path Traversal in Flow ID File Operations ### Summary `@openhop/server` passes unsanitized HTTP route parameters directly to `path.join()` when c...
HIGH??????????NVD52 minutes ago
CVE-2026-59177
## Summary On the Home Assistant add-on, the dashboard serves a trusted ingress site that skips authentication because the supervisor authenticates t...
HIGH??????????NVD53 minutes ago
CVE-2026-59176
## MCP `set_functype_version` Package Alias RCE via Unsanitized pnpm install + Dynamic Import ### Summary The `set_functype_version` MCP tool in `fu...
HIGH??????????NVD55 minutes ago
CVE-2026-59172
## Impact In Joker versions before 1.8.2, `joker --lint <file>` located a `.jokerd/` directory by walking up from the linted file and executed ...
HIGH??????????NVD55 minutes ago
CVE-2026-59160
## Unauthenticated Network-Exposed Turborepo Task Execution via /api/run ### Summary `@yeger/turbo-graph` starts its embedded Next.js server without...
HIGH??????????NVD56 minutes ago
CVE-2026-59158
## Public Runtime Config Exposes Ollama API Key to Browser Clients ### Summary `nuxt-ollama@1.2.26` unconditionally merges all module options — in...
HIGH??????????NVD56 minutes ago
CVE-2026-59157
## Description Before 1.22, if the Basic Auth (`htpasswd`) middleware was not configured, all incoming HTTP headers were blindly forwarded to the webh...
MEDIUM??????????NVD57 minutes ago
CVE-2026-87931
A vulnerability has been found in Behavioral Technology Group Pavlok Behavioral Conditioning Wearable up to 20260707. Impacted is an unknown function ...
CRITICAL??????????NVD59 minutes ago
CVE-2026-55864
### Summary An unauthenticated server-side request forgery vulnerability lets any anonymous user make the GeoNetwork server issue arbitrary outbound H...
HIGH??????????NVD1 hour ago
CVE-2026-87926
A flaw has been found in Rizwan17 inventory-management-system up to bfe78a330d01bb26b9daec5dc9ecd5c77900e03f. This issue affects some unknown processi...
MEDIUM??????????NVD1 hour ago
CVE-2026-87925
A vulnerability was detected in Rizwan17 inventory-management-system up to bfe78a330d01bb26b9daec5dc9ecd5c77900e03f. This vulnerability affects the fu...
HIGH??????????NVD1 hour ago
CVE-2026-87924
A security vulnerability has been detected in Rizwan17 inventory-management-system up to bfe78a330d01bb26b9daec5dc9ecd5c77900e03f. This affects an unk...
MEDIUM??????????NVD1 hour ago
CVE-2026-15460
The Bluetooth Classic (BR/EDR) L2CAP receive handler bt_l2cap_br_recv() in subsys/bluetooth/host/classic/l2cap_br.c dispatched inbound data PDUs based...
MEDIUM??????????NVD2 hours ago
CVE-2026-87923
A weakness has been identified in Rizwan17 inventory-management-system up to bfe78a330d01bb26b9daec5dc9ecd5c77900e03f. Affected by this issue is some ...
MEDIUM??????????NVD2 hours ago
CVE-2026-88002
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.5.0 until 0.11.1, the message-chain reconstruction helper...
MEDIUM??????????NVD2 hours ago
CVE-2026-88000
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.10.0 until 0.11.1, DELETE /api/v1/chats/{id}/messages/{me...
MEDIUM??????????NVD2 hours ago
CVE-2026-87999
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. Prior to 0.11.1, POST /api/v1/retrieval/process/web and POST /ap...
HIGH??????????NVD2 hours ago
CVE-2026-87998
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.10.0 until 0.11.1, DELETE /api/v1/knowledge/{id}/delete i...
HIGH??????????NVD2 hours ago
CVE-2026-87997
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.10.0 until 0.11.1, POST /api/chat/completions and POST /a...
MEDIUM??????????NVD2 hours ago