Critical Alert 2 Active Exploits Detected Today

CVE-2022-0492 Linux Kernel Improper Authentication Vulnerability →
CVE-2025-48595 Android Framework Integer Overflow Vulnerability →
Powered by CVE Watchtower
×

CVE Watchtower

Advanced Threat Data Export

Filter and download the raw CVE repository (CSV/JSON) for SIEM integration and internal reporting.

Data export is locked. Upgrade your package to enable filtering and downloading.

πŸ”” Premium Features
πŸ” Filter Threats
Title
SeverityEPSS (30-Day)
PoCActively ExploitedSourceDate
CVE-2026-45289
CloudburstMC Protocol is a protocol library for Minecraft Bedrock Edition. Prior to version 3.0.0.Beta12-20260420.182526-15, CloudburstMC Protocol is ...
MEDIUMπŸ”’ LOCKED??????????NVD8 hours ago
CVE-2026-42849
authentik is an open-source identity provider. Prior to versions 2025.12.5 and 2026.2.3, due to the implementation of stages in the SFE (Simple Flow E...
CRITICALπŸ”’ LOCKED??????????NVD8 hours ago
CVE-2026-47201
authentik is an open-source identity provider. Prior to versions 2025.12.5, 2026.2.3, and 2026.5.1, authentik's SAML Source ACS endpoint is vulne...
HIGHπŸ”’ LOCKED??????????NVD8 hours ago
CVE-2026-10650
A flaw has been found in warmcat libwebsockets up to 4.5.8. This issue affects the function lws_ssh_parse_plaintext of the file plugins/protocol_lws_s...
MEDIUMπŸ”’ LOCKED??????????NVD8 hours ago
CVE-2026-8936
Fixed a VM panic caused by unbounded recursion in the grpcfuse kernel module when a container created deeply nested directories on a bind-mounted host...
UNKNOWNπŸ”’ LOCKED??????????NVD8 hours ago
CVE-2022-4992
DrΓ€ger Infinity Acute Care System and Standalone Infinity M540 patient monitors versions VG4.1.1, VG4.0.3, and lower (with VG4.2 partially affected) ...
HIGHπŸ”’ LOCKED??????????NVD8 hours ago
CVE-2026-49144
BrowserStack Runner through 0.9.5 contains a path traversal vulnerability in the _default HTTP handler in lib/server.js that allows unauthenticated ne...
MEDIUMπŸ”’ LOCKED??????????NVD9 hours ago
CVE-2026-49143
BrowserStack Runner through 0.9.5 contains a remote code execution vulnerability in the /_log HTTP handler that allows unauthenticated network-adjacen...
HIGHπŸ”’ LOCKED??????????NVD9 hours ago
CVE-2026-41569
authentik is an open-source identity provider. Prior to version 2026.2.3, the WS-Federation provider validates the user-supplied wreply parameter usin...
UNKNOWNπŸ”’ LOCKED??????????NVD9 hours ago
CVE-2026-10624
A vulnerability has been found in SourceCodester Human Resource Management 1.0. Affected by this vulnerability is an unknown functionality of the file...
MEDIUMπŸ”’ LOCKED??????????NVD9 hours ago
CVE-2026-5076
The ARMember Premium plugin for WordPress is vulnerable to an insecure password reset mechanism in all versions up to, and including, 7.3.1. The plugi...
CRITICALπŸ”’ LOCKED??????????NVD9 hours ago
CVE-2026-5074
The ARMember Premium plugin for WordPress is vulnerable to SQL Injection via the 'sSortDir_0' parameter of the `get_private_content_data` AJ...
MEDIUMπŸ”’ LOCKED??????????NVD9 hours ago
CVE-2026-5073
The ARMember Premium plugin for WordPress is vulnerable to SQL Injection via the 'order' parameter of the 'arm_directory_paging_action&...
HIGHπŸ”’ LOCKED??????????NVD9 hours ago
CVE-2026-48682
FastNetMon Community Edition through 1.2.9 contains an out-of-bounds read in the IPv4 packet parser. In src/simple_packet_parser_ng.cpp, after validat...
UNKNOWNπŸ”’ LOCKED??????????NVD9 hours ago
CVE-2026-42342
React Router is a router for React. In versions 7.0.0 through 7.14.x of react-router and versions 2.10.0 through 2.17.4 of @remix-run/server-runtime, ...
HIGHπŸ”’ LOCKED??????????NVD9 hours ago
CVE-2026-42211
React Router is a router for React. In versions 7.0.0 through 7.14.1, when using Framework Mode, a combination of steps could potentially allow unauth...
HIGHπŸ”’ LOCKED??????????NVD9 hours ago
CVE-2026-38967
CrowCpp Crow through v1.3.1 HTTP is vulnerable to response header injection via unvalidated response header values.
UNKNOWNπŸ”’ LOCKED??????????NVD9 hours ago
CVE-2026-35049
wire-ios is an iOS client for the Wire secure messaging application. Prior to version 4.16.0, upon receiving a crafted malicious Proteus external mess...
MEDIUMπŸ”’ LOCKED??????????NVD9 hours ago
CVE-2026-34993
AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.14.0, using ``CookieJar.load()`` with untrusted inp...
MEDIUMπŸ”’ LOCKED??????????NVD9 hours ago
CVE-2026-34077
React Router is a router for React. In versions 7.7.0 through 7.13.1, when using React Router's unstable React Server Components (RSC) APIs, ther...
HIGHπŸ”’ LOCKED??????????NVD9 hours ago