Critical Alert 2 Active Exploits Detected Today

CVE-2026-72530 TrueConf Server Code Injection Vulnerability →
CVE-2026-72529 TrueConf Server Missing Authentication for Critical Function Vulnerability →
Powered by CVE Watchtower
×
August 21, 2026

CVE Watchtower

Advanced Threat Data Export

Filter and download the raw CVE repository (CSV/JSON) for SIEM integration and internal reporting.

Data export is locked. Upgrade your package to enable filtering and downloading.

🔔 Premium Features
🔍 Filter Threats
Title
SeverityPoCActively ExploitedSourceDate
CVE-2026-63328
Trivy is a security scanner. Prior to 0.72.0, plugin manifest metadata is used by pkg/plugin/manager.go to construct paths under ~/.trivy/plugins with...
UNKNOWN??????????NVD2 days ago
CVE-2026-68939
Pyenv provides simple Python version management. Prior to 2.8.0, is_version_safe() in libexec/pyenv-version-file-read accepts shell glob metacharacter...
UNKNOWN??????????NVD2 days ago
CVE-2026-71539
n8n is an open source workflow automation platform. Prior to 1.123.64, 2.29.8, and 2.30.1, the Git node clone operation allows an authenticated workfl...
UNKNOWN??????????NVD2 days ago
CVE-2026-75898
RAGFlow before 0.26.3 contains a server-side request forgery vulnerability in the agent workflow "Invoke" component (agent/component/invoke....
HIGH??????????NVD2 days ago
CVE-2026-73692
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
UNKNOWN??????????NVD2 days ago
CVE-2026-50575
BetterDesk is a remote desktop management solution. BetterDesk versions through 2.3.0 improperly invalidate deleted device identities, allowing an una...
HIGH??????????NVD2 days ago
CVE-2026-32468
Unauthenticated Sensitive Data Exposure in Duitku Payment Gateway <= 2.11.14 versions.
HIGH??????????NVD2 days ago
CVE-2026-32467
Subscriber Server Side Request Forgery (SSRF) in [Aotuman] Grab WeChat Articles <= 2.0.1 versions.
MEDIUM??????????NVD2 days ago
CVE-2026-32466
Subscriber SQL Injection in Gravity Forms Bookings premium <= 2.1 versions.
HIGH??????????NVD2 days ago
CVE-2026-32465
Customer PHP Object Injection in Essential Real Estate <= 5.3.3 versions.
HIGH??????????NVD2 days ago
CVE-2026-32464
Unauthenticated Local File Inclusion in Theme Test Drive <= 2.9.1 versions.
HIGH??????????NVD2 days ago
CVE-2026-32463
Contributor Arbitrary File Upload in Sync Post With Other Site <= 1.9.3 versions.
CRITICAL??????????NVD2 days ago
CVE-2026-32444
Contributor Remote Code Execution (RCE) in Cwicly <= 1.4.4 versions.
CRITICAL??????????NVD2 days ago
CVE-2026-32333
Unauthenticated Cross Site Scripting (XSS) in Mayosis Core <= 5.4.7 versions.
HIGH??????????NVD2 days ago
CVE-2026-28571
Unauthenticated Broken Access Control in FormyChat <= 2.15.7 versions.
HIGH??????????NVD2 days ago
CVE-2026-28570
Unauthenticated Local File Inclusion in Vavo Core <= 2.3.0 versions.
HIGH??????????NVD2 days ago
CVE-2026-28569
Unauthenticated Cross Site Scripting (XSS) in SSL Zen <= 4.7.43 versions.
HIGH??????????NVD2 days ago
CVE-2026-28568
Unauthenticated Cross Site Scripting (XSS) in Quill Forms <= 5.7.1 versions.
HIGH??????????NVD2 days ago
CVE-2026-28567
Unauthenticated Broken Access Control in WP Sort Order <= 1.3.5 versions.
HIGH??????????NVD2 days ago
CVE-2026-28192
Unauthenticated Arbitrary File Upload in Piotnet Addons For Elementor Pro <= 7.1.67 versions.
CRITICAL??????????NVD2 days ago