Critical Alert 2 Active Exploits Detected Today

CVE-2026-72530 TrueConf Server Code Injection Vulnerability →
CVE-2026-72529 TrueConf Server Missing Authentication for Critical Function Vulnerability →
Powered by CVE Watchtower
×
August 21, 2026

CVE Watchtower

Advanced Threat Data Export

Filter and download the raw CVE repository (CSV/JSON) for SIEM integration and internal reporting.

Data export is locked. Upgrade your package to enable filtering and downloading.

🔔 Premium Features
🔍 Filter Threats
Title
SeverityPoCActively ExploitedSourceDate
CVE-2026-75926
Hugo 0.161.0 placed the Node asset pipelines behind the Node.js permission model so that code running through PostCSS, Babel, or TailwindCSS could not...
HIGH??????????NVD2 days ago
CVE-2026-73073
Vim is an open source, command line text editor. Prior to 9.2.0845, StructMembers() in runtime/autoload/ccomplete.vim constructs and executes a vimgre...
UNKNOWN??????????NVD2 days ago
CVE-2026-75914
CodeWhale versions before 0.8.64 contain a path traversal vulnerability in the image_analyze tool that fails to canonicalize symlinks before reading f...
HIGH??????????NVD2 days ago
CVE-2026-75915
CodeWhale versions before 0.8.64 contain an environment variable exposure vulnerability in the js_execution tool that fails to scrub parent process en...
HIGH??????????NVD2 days ago
CVE-2026-75913
CodeWhale (codewhale / codewhale-tui) versions >= 0.8.41 and < 0.8.64 contain an argument injection vulnerability in the git_show tool. The mode...
CRITICAL??????????NVD2 days ago
CVE-2026-75912
CodeWhale versions before 0.8.64 contain an argument injection vulnerability in the git_blame tool that allows attackers to read arbitrary files by in...
HIGH??????????NVD2 days ago
CVE-2026-75911
CodeWhale versions before 0.8.64 fail to properly validate the allow_shell configuration parameter from project config files, allowing attackers to en...
HIGH??????????NVD2 days ago
CVE-2026-75904
libmodplug through 0.8.9.1 contains an out-of-bounds read in pat_smplooped in src/load_pat.cpp. The function validates only the upper bound of its sam...
LOW??????????NVD2 days ago
CVE-2026-75859
CodeWhale versions before 0.8.64 fail to validate file paths in the project config instructions field, allowing attackers to read arbitrary files on t...
HIGH??????????NVD2 days ago
CVE-2026-75858
CodeWhale (packages codewhale / codewhale-tui) versions >= 0.8.41 and < 0.8.64 contain a remote code execution vulnerability in the rlm_eval too...
HIGH??????????NVD2 days ago
CVE-2026-75857
CodeWhale versions >= 0.8.41 and < 0.8.64 contain a vulnerability in the exec_shell_interact (alias exec_interact) tool, whose approval_requirem...
HIGH??????????NVD2 days ago
CVE-2026-75856
CodeWhale before 0.8.64 contains a server-side request forgery bypass vulnerability in DNS pinning logic that fails to prevent time-of-check-time-of-u...
HIGH??????????NVD2 days ago
CVE-2026-62357
Dragonfly is an in-memory data store built for modern application workloads. Prior to 1.40.0, CMS.INITBYDIM and CMS.INITBYPROB accept dimensions whose...
UNKNOWN??????????NVD2 days ago
CVE-2026-75890
Rejected reason: Duplicate of CVE-2026-50236. This CVE ID was reserved in error for a finding that already had an existing CVE assignment.
UNKNOWN??????????NVD2 days ago
CVE-2026-75032
A flaw was found in BlueZ. Insufficient validation of packet length fields in GetFolderItems responses within the Audio/Video Remote Control Profile (...
MEDIUM??????????NVD2 days ago
CVE-2026-74015
Unauthenticated SQL Injection in Readabler < 2.0.18 versions.
CRITICAL??????????NVD2 days ago
CVE-2026-74009
Unauthenticated Insecure Direct Object References (IDOR) in Razorpay for WooCommerce <= 4.8.7 versions.
MEDIUM??????????NVD2 days ago
CVE-2026-74007
Unauthenticated Sensitive Data Exposure in 3D FlipBook – PDF Flipbook Viewer, Flipbook Image Gallery <= 1.16.20 versions.
MEDIUM??????????NVD2 days ago
CVE-2026-74006
Contributor Broken Access Control in WP Table Builder <= 2.2.0 versions.
MEDIUM??????????NVD2 days ago
CVE-2026-74012
Deserialization of Untrusted Data vulnerability in TaxoPress allows Object Injection. This issue affects TaxoPress: from n/a through 3.51.0.
HIGH??????????NVD2 days ago