Critical Alert 2 Active Exploits Detected Today

CVE-2026-72530 TrueConf Server Code Injection Vulnerability →
CVE-2026-72529 TrueConf Server Missing Authentication for Critical Function Vulnerability →
Powered by CVE Watchtower
×
August 21, 2026

CVE Watchtower

Advanced Threat Data Export

Filter and download the raw CVE repository (CSV/JSON) for SIEM integration and internal reporting.

Data export is locked. Upgrade your package to enable filtering and downloading.

🔔 Premium Features
🔍 Filter Threats
Title
SeverityPoCActively ExploitedSourceDate
CVE-2026-74008
Unauthenticated Sensitive Data Exposure in Shortcodes and extra features for Phlox theme <= 2.17.22 versions.
MEDIUM??????????NVD2 days ago
CVE-2026-74004
Subscriber Broken Access Control in Gravity Booster – Styles & Layouts for Gravity Forms <= 6.0 versions.
MEDIUM??????????NVD2 days ago
CVE-2026-74003
Contributor Broken Access Control in RomethemeForm For Elementor <= 1.2.6 versions.
MEDIUM??????????NVD2 days ago
CVE-2026-73996
Unauthenticated Arbitrary File Upload in Masteriyo - LMS <= 2.3.2 versions.
CRITICAL??????????NVD2 days ago
CVE-2026-73995
Subscriber Broken Authentication in User Registration <= 5.2.6 versions.
MEDIUM??????????NVD2 days ago
CVE-2026-73997
Unauthenticated Denial of Service Attack in Starter Templates by Kadence WP <= 2.3.3 versions.
HIGH??????????NVD2 days ago
CVE-2026-73994
Unauthenticated Broken Access Control in Charitable <= 1.8.11.3 versions.
HIGH??????????NVD2 days ago
CVE-2026-73426
Trix is a what-you-see-is-what-you-get rich text editor for everyday writing. Prior to 2.1.17, Trix is vulnerable to cross-site scripting when a data-...
MEDIUM??????????NVD2 days ago
CVE-2026-73404
Subscriber Broken Access Control in MasterStudy LMS <= 3.7.41 versions.
MEDIUM??????????NVD2 days ago
CVE-2026-73399
Unauthenticated Broken Authentication in Flutterwave WooCommerce <= 3.3.0 versions.
MEDIUM??????????NVD2 days ago
CVE-2026-73398
Unauthenticated Broken Authentication in Piraeus Bank WooCommerce Payment Gateway 3.2.0 versions.
MEDIUM??????????NVD2 days ago
CVE-2026-73400
Unauthenticated Local File Inclusion in Restaurant Menu by MotoPress <= 2.4.11 versions.
HIGH??????????NVD2 days ago
CVE-2026-73397
Unauthenticated Deserialization of untrusted data in Youzify <= 1.3.7 versions.
CRITICAL??????????NVD2 days ago
CVE-2026-73396
Subscriber Broken Authentication in MWB HubSpot for WooCommerce <= 1.6.7 versions.
HIGH??????????NVD2 days ago
CVE-2026-73393
Unauthenticated Cross Site Scripting (XSS) in Subscribe2 <= 10.46 versions.
HIGH??????????NVD2 days ago
CVE-2026-73392
Unauthenticated SQL Injection in Super Store Finder <= 7.8 versions.
CRITICAL??????????NVD2 days ago
CVE-2026-73382
Unauthenticated Cross Site Scripting (XSS) in Site Reviews <= 8.2.0 versions.
HIGH??????????NVD2 days ago
CVE-2026-73380
Unauthenticated PHP Object Injection in Popup by Supsystic <= 1.13.0 versions.
CRITICAL??????????NVD2 days ago
CVE-2026-73395
Unauthenticated Insecure Direct Object References (IDOR) in Booking calendar, Appointment Booking System <= 3.2.36 versions.
MEDIUM??????????NVD2 days ago
CVE-2026-73383
Shop manager Arbitrary File Download in CTX Feed <= 6.6.47 versions.
MEDIUM??????????NVD2 days ago