CVE Watchtower

🔍 Filter Threats
🎁7-Day Free Trial — Try Pro or Team, no card required.
📧Email Delivery — Threat intel straight to your inbox.
♾️Unlimited Vendors — Track your entire stack.
🚨All New CVEs — Be the first to know.
📈EPSS Spike Alerts — Catch rising risk before it peaks.
🎯Custom EPSS/CVSS — Filter noise, focus on risk.
🛡️Exploit Intel — A 2nd confirmed-exploit signal beyond KEV.
🐙GitHub Issues — Auto-tracked, no duplicates.
📬Weekly Digest — One clean summary, not inbox spam.
🏷️Watchlist Groups — Tag alerts by team (Infra/AppSec/SOC).
💬Webhooks — Slack & Teams integration.
🔀Smart Routing — Critical alerts to one channel, rest to another.
🚫Ad-Free — Uninterrupted experience.
🎁7-Day Free Trial — Try Pro or Team, no card required.
📧Email Delivery — Threat intel straight to your inbox.
♾️Unlimited Vendors — Track your entire stack.
🚨All New CVEs — Be the first to know.
📈EPSS Spike Alerts — Catch rising risk before it peaks.
🎯Custom EPSS/CVSS — Filter noise, focus on risk.
🛡️Exploit Intel — A 2nd confirmed-exploit signal beyond KEV.
🐙GitHub Issues — Auto-tracked, no duplicates.
📬Weekly Digest — One clean summary, not inbox spam.
🏷️Watchlist Groups — Tag alerts by team (Infra/AppSec/SOC).
💬Webhooks — Slack & Teams integration.
🔀Smart Routing — Critical alerts to one channel, rest to another.
🚫Ad-Free — Uninterrupted experience.
Title
SeverityPoCActively ExploitedSourceDate
???-????-????
??????????????????????????????????
??????????????????????????????????
HIGH??????????SA23 hours ago
???-????-????
??????????????????????????????????
??????????????????????????????????
HIGH??????????SA23 hours ago
???-????-????
??????????????????????????????????
??????????????????????????????????
CRITICAL??????????SA1 day ago
???-????-????
??????????????????????????????????
??????????????????????????????????
CRITICAL??????????SA1 day ago
???-????-???? R
??????????????????????????????????
??????????????????????????????????
CRITICAL??????????SA2 days ago
CVE-2026-4894
A vulnerability has been identified regarding insufficient validation in the Frappe Cloud/ERPNext authentication process, which allows multiple email ...
MEDIUM??????????NVD29 minutes ago
CVE-2026-71896
An authorization vulnerability in Apache DolphinScheduler allows authenticated users to retrieve other users' account information through the /do...
UNKNOWN??????????NVD34 minutes ago
CVE-2026-71895
An authorization vulnerability in Apache DolphinScheduler allows authenticated non-admin users to retrieve Kubernetes configuration data intended for ...
UNKNOWN??????????NVD36 minutes ago
CVE-2026-71183
An authorization vulnerability in Apache DolphinScheduler allows authenticated users to obtain information about data sources they are not authorized ...
UNKNOWN??????????NVD38 minutes ago
CVE-2026-66087
An authorization bypass vulnerability in Apache DolphinScheduler allows authenticated users to operate task instance in projects they are not authoriz...
UNKNOWN??????????NVD43 minutes ago
CVE-2026-66084
An authorization bypass vulnerability in Apache DolphinScheduler allows authenticated users to modify task definitions in projects they are not author...
UNKNOWN??????????NVD55 minutes ago
CVE-2026-66082
An authorization bypass vulnerability in Apache DolphinScheduler allows authenticated users to perform unauthorized operations on workflow schedules, ...
UNKNOWN??????????NVD56 minutes ago
CVE-2026-107466
A flaw was found in flatpak-builder. This vulnerability allows an attacker to cause information disclosure by convincing a user or continuous integrat...
MEDIUM??????????NVD56 minutes ago
CVE-2026-89191
Unsanitised input in the "template name" field of SQLView KRIS's Workflow Template feature is rendered in "onclick" attribute...
MEDIUM??????????NVD58 minutes ago
CVE-2026-12260
SQL injection in the NetBoard CRM demo platform; specifically, the vulnerable component is the ‘user-name’ POST parameter in the ‘/module/auth/r...
CRITICAL??????????NVD1 hour ago
CVE-2026-93699
Argument injection in WP Toolkit for cPanel allows local users to execute arbitrary code as other accounts on the same server.
HIGH??????????NVD1 hour ago
CVE-2026-85097
The Bricksforge plugin for WordPress is vulnerable to unauthenticated arbitrary file upload in versions up to, and including, 3.1.8.9. This is due to ...
CRITICAL??????????NVD1 hour ago
CVE-2026-87428
In Brocade ASCG before 3.5.0, a  local unauthorized user on the ASCG VM who can issue a request to the SANnav host network namespace can extract stor...
HIGH??????????NVD2 hours ago
CVE-2026-87426
An unauthenticated network-based attacker can query specific internal management endpoints on Brocade ASCG versions before 3.5.0 to enumerate the conf...
MEDIUM??????????NVD2 hours ago
CVE-2026-87425
An unauthenticated remote attacker can modify the TLS client trust store in Brocade ASCG versions before 3.5.0. By supplying an unauthorized Certifica...
HIGH??????????NVD2 hours ago
CVE-2026-87424
A vulnerability in the SupportLink API authentication component of Brocade ASCG versions prior to 3.5.0 allows an attacker to bypass authentication ac...
HIGH??????????NVD2 hours ago
CVE-2026-85490
When Brocade ASCG before 3.5.0 processes support bundle archives ingested from remote compromised endpoints, the application fails to sanitize path tr...
HIGH??????????NVD2 hours ago
CVE-2026-85489
An authentication flaw exists in the Brocade ASCG administrative management service component. An unauthenticated network user can issue direct API re...
HIGH??????????NVD2 hours ago
CVE-2026-85488
Brocade ASCG before 3.5.0 has a well-known Brocade default password embedded in a script distributed to every customer. Any local authenticated user w...
HIGH??????????NVD2 hours ago
CVE-2026-85487
A path traversal vulnerability exists in the HTTP service component of Brocade ASCG versions before 3.5.0. An unauthenticated attacker on the local ne...
HIGH??????????NVD2 hours ago
🎁7-Day Free Trial — Try Pro or Team, no card required.
📧Email Delivery — Threat intel straight to your inbox.
♾️Unlimited Vendors — Track your entire stack.
🚨All New CVEs — Be the first to know.
📈EPSS Spike Alerts — Catch rising risk before it peaks.
🎯Custom EPSS/CVSS — Filter noise, focus on risk.
🛡️Exploit Intel — A 2nd confirmed-exploit signal beyond KEV.
🐙GitHub Issues — Auto-tracked, no duplicates.
📬Weekly Digest — One clean summary, not inbox spam.
🏷️Watchlist Groups — Tag alerts by team (Infra/AppSec/SOC).
💬Webhooks — Slack & Teams integration.
🔀Smart Routing — Critical alerts to one channel, rest to another.
🚫Ad-Free — Uninterrupted experience.
🎁7-Day Free Trial — Try Pro or Team, no card required.
📧Email Delivery — Threat intel straight to your inbox.
♾️Unlimited Vendors — Track your entire stack.
🚨All New CVEs — Be the first to know.
📈EPSS Spike Alerts — Catch rising risk before it peaks.
🎯Custom EPSS/CVSS — Filter noise, focus on risk.
🛡️Exploit Intel — A 2nd confirmed-exploit signal beyond KEV.
🐙GitHub Issues — Auto-tracked, no duplicates.
📬Weekly Digest — One clean summary, not inbox spam.
🏷️Watchlist Groups — Tag alerts by team (Infra/AppSec/SOC).
💬Webhooks — Slack & Teams integration.
🔀Smart Routing — Critical alerts to one channel, rest to another.
🚫Ad-Free — Uninterrupted experience.