Critical Alert 2 Active Exploits Detected Today

CVE-2026-72530 TrueConf Server Code Injection Vulnerability →
CVE-2026-72529 TrueConf Server Missing Authentication for Critical Function Vulnerability →
Powered by CVE Watchtower
×
August 21, 2026

CVE Watchtower

Advanced Threat Data Export

Filter and download the raw CVE repository (CSV/JSON) for SIEM integration and internal reporting.

Data export is locked. Upgrade your package to enable filtering and downloading.

🔔 Premium Features
🔍 Filter Threats
Title
SeverityPoCActively ExploitedSourceDate
CVE-2026-13360
The Cookie Banner for GDPR / CCPA – WPLP Cookie Consent plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'regionArray&...
HIGH??????????NVD6 days ago
???-????-????
??????????????????????????????????
??????????????????????????????????
CRITICAL??????????SA6 days ago
???-????-????
??????????????????????????????????
??????????????????????????????????
CRITICAL??????????SA6 days ago
CVE-2026-8840
The Booking calendar, Appointment Booking System plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.2....
MEDIUM??????????NVD6 days ago
CVE-2026-16080
The Image Uploader for Welcart plugin for WordPress is vulnerable to generic SQL Injection via the 'post_title' parameter in all versions up...
MEDIUM??????????NVD6 days ago
CVE-2026-15965
The MaxUpload – Big File Uploads – Increase Maximum File Upload Size plugin for WordPress is vulnerable to Arbitrary File Upload in all versions u...
HIGH??????????NVD6 days ago
CVE-2026-15341
The User Session Synchronizer plugin for WordPress is vulnerable to Authentication Bypass leading to Account Takeover in all versions up to, and inclu...
CRITICAL??????????NVD6 days ago
CVE-2026-15312
The Propovoice: All-in-One Client Management System plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1...
HIGH??????????NVD6 days ago
CVE-2026-15303
The 6Storage Rentals plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.27.0. This is due to the six_stor...
CRITICAL??????????NVD6 days ago
CVE-2026-15162
The Object Sync for Salesforce plugin is vulnerable to unauthenticated SQL Injection via the wordpress_object_type parameter of its /wp-json/object-sy...
HIGH??????????NVD6 days ago
CVE-2026-15001
The bLoyal: Loyalty & Promotions by bLoyal plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.1.61...
HIGH??????????NVD6 days ago
CVE-2026-14484
The RapiSafe – Secure Multi File Upload for Contact Form 7 plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file pa...
CRITICAL??????????NVD6 days ago
CVE-2026-14433
The Online Booking & Scheduling Calendar for WordPress by vcita plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'bu...
HIGH??????????NVD6 days ago
CVE-2026-12128
The Pinpoint Booking System – Version 2 plugin for WordPress is vulnerable to Price Manipulation via the `cart_data` parameter in all versions up to...
MEDIUM??????????NVD6 days ago
CVE-2026-74247
A flaw was found in Red Hat Quay. A user with FEATURE_BUILD_SUPPORT enabled and repository write access can exploit a Server-Side Request Forgery (SSR...
MEDIUM??????????NVD6 days ago
CVE-2026-74245
A flaw was found in Red Hat Quay's exported logs feature. An unauthenticated attacker with a valid file ID could download exported action logs wi...
MEDIUM??????????NVD6 days ago
CVE-2026-74244
A flaw was found in Red Hat Quay's Stripe billing webhook handler. This vulnerability allows an unauthenticated attacker to forge billing events ...
MEDIUM??????????NVD6 days ago
CVE-2026-74243
A flaw was found in Red Hat Quay. When the SECURITY_SCANNER_V4_PSK (pre-shared key) is not set, a remote unauthenticated attacker can send POST reques...
MEDIUM??????????NVD6 days ago
CVE-2026-74242
A flaw was found in Red Hat Quay. An administrator of any repository, by knowing or guessing a target notification's Universally Unique Identifie...
MEDIUM??????????NVD6 days ago
CVE-2026-74241
A flaw was found in Red Hat Quay's external Lightweight Directory Access Protocol (LDAP) authentication handling. When an LDAP referral is return...
MEDIUM??????????NVD6 days ago