Critical Alert 2 Active Exploits Detected Today

CVE-2026-72530 TrueConf Server Code Injection Vulnerability →
CVE-2026-72529 TrueConf Server Missing Authentication for Critical Function Vulnerability →
Powered by CVE Watchtower
×
August 21, 2026

CVE Watchtower

Advanced Threat Data Export

Filter and download the raw CVE repository (CSV/JSON) for SIEM integration and internal reporting.

Data export is locked. Upgrade your package to enable filtering and downloading.

🔔 Premium Features
🔍 Filter Threats
Title
SeverityPoCActively ExploitedSourceDate
CVE-2026-66644
Contributor Cross Site Scripting (XSS) in Typing Effect <= 1.3.7 versions.
MEDIUM??????????NVD2 days ago
CVE-2026-66643
Contributor Cross Site Scripting (XSS) in Wufoo Shortcode <= 1.55 versions.
MEDIUM??????????NVD2 days ago
CVE-2026-66645
Contributor Cross Site Scripting (XSS) in Table Of Contents Block <= 1.5.0 versions.
MEDIUM??????????NVD2 days ago
CVE-2026-66641
Contributor Cross Site Scripting (XSS) in Video Conferencing with Zoom <= 4.6.8 versions.
MEDIUM??????????NVD2 days ago
CVE-2026-66640
Contributor Cross Site Scripting (XSS) in Login With Ajax <= 4.5.1 versions.
MEDIUM??????????NVD2 days ago
CVE-2026-66638
Contributor Cross Site Scripting (XSS) in Frontend Admin by DynamiApps <= 3.29.10 versions.
MEDIUM??????????NVD2 days ago
CVE-2026-66637
Contributor Cross Site Scripting (XSS) in Featured Video Plus <= 2.3.3 versions.
MEDIUM??????????NVD2 days ago
CVE-2026-66636
Contributor Cross Site Scripting (XSS) in Wise Chat <= 3.4 versions.
MEDIUM??????????NVD2 days ago
CVE-2026-66635
Unauthenticated Cross Site Request Forgery (CSRF) in Slider by 10Web <= 1.2.62 versions.
HIGH??????????NVD2 days ago
CVE-2026-66639
Contributor Cross Site Scripting (XSS) in WPZOOM Forms – Contact Form Plugin for Gutenberg <= 2.0.4 versions.
MEDIUM??????????NVD2 days ago
CVE-2026-66633
Unauthenticated Cross Site Scripting (XSS) in Fluent Forms Pro Add On Pack < 6.2.12 versions.
HIGH??????????NVD2 days ago
CVE-2026-66629
Unauthenticated Cross Site Scripting (XSS) in Kirki <= 6.2.3 versions.
HIGH??????????NVD2 days ago
CVE-2026-66627
Contributor Arbitrary File Upload in GP Premium <= 2.5.5 versions.
CRITICAL??????????NVD2 days ago
CVE-2026-66622
Unauthenticated SQL Injection in Depicter Slider <= 4.8.0 versions.
HIGH??????????NVD2 days ago
CVE-2026-66620
Editor PHP Object Injection in OptionTree <= 2.7.3 versions.
HIGH??????????NVD2 days ago
CVE-2026-66634
Subscriber Insecure Direct Object References (IDOR) in Modal Survey <= 2.0.2.2.3 versions.
MEDIUM??????????NVD2 days ago
CVE-2026-66621
Unauthenticated Cross Site Scripting (XSS) in Ultimate Dashboard <= 3.11.2 versions.
HIGH??????????NVD2 days ago
CVE-2026-63639
Valkey is a distributed key-value database. Prior to 7.2.14, 8.0.10, 8.1.9, 9.0.5, and 9.1.1, Valkey's RESTORE command accepts a malformed RDB st...
HIGH??????????NVD2 days ago
CVE-2026-61407
Dell Watchdog Timer Driver versions prior to 2.0.0.1 contain an Exposed IOCTL with Insufficient Access Control vulnerability. A low privileged attacke...
HIGH??????????NVD2 days ago
CVE-2026-59949
yawkat LZ4 Java provides LZ4 compression for Java. Prior to 1.11.1, JNI-backed XXHash implementations fail to validate the byte array object and the o...
MEDIUM??????????NVD2 days ago