CVE Watchtower

🔍 Filter Threats
🎁7-Day Free Trial — Try Pro or Team, no card required.
📧Email Delivery — Threat intel straight to your inbox.
♾️Unlimited Vendors — Track your entire stack.
🚨All New CVEs — Be the first to know.
📈EPSS Spike Alerts — Catch rising risk before it peaks.
🎯Custom EPSS/CVSS — Filter noise, focus on risk.
🛡️Exploit Intel — A 2nd confirmed-exploit signal beyond KEV.
🐙GitHub Issues — Auto-tracked, no duplicates.
📬Weekly Digest — One clean summary, not inbox spam.
🏷️Watchlist Groups — Tag alerts by team (Infra/AppSec/SOC).
💬Webhooks — Slack & Teams integration.
🔀Smart Routing — Critical alerts to one channel, rest to another.
🚫Ad-Free — Uninterrupted experience.
🎁7-Day Free Trial — Try Pro or Team, no card required.
📧Email Delivery — Threat intel straight to your inbox.
♾️Unlimited Vendors — Track your entire stack.
🚨All New CVEs — Be the first to know.
📈EPSS Spike Alerts — Catch rising risk before it peaks.
🎯Custom EPSS/CVSS — Filter noise, focus on risk.
🛡️Exploit Intel — A 2nd confirmed-exploit signal beyond KEV.
🐙GitHub Issues — Auto-tracked, no duplicates.
📬Weekly Digest — One clean summary, not inbox spam.
🏷️Watchlist Groups — Tag alerts by team (Infra/AppSec/SOC).
💬Webhooks — Slack & Teams integration.
🔀Smart Routing — Critical alerts to one channel, rest to another.
🚫Ad-Free — Uninterrupted experience.
Title
SeverityPoCActively ExploitedSourceDate
CVE-2026-39781
Unauthenticated Cross Site Scripting (XSS) in Document Gallery <= 5.1.1 versions.
HIGH??????????NVD1 day ago
CVE-2026-39780
Unauthenticated Cross Site Scripting (XSS) in Youzify <= 1.3.7 versions.
HIGH??????????NVD1 day ago
CVE-2026-39778
Unauthenticated Cross Site Scripting (XSS) in Ansar Import – One Click Starter Sites – for Elementor & Themes <= 2.1.2 versions.
HIGH??????????NVD1 day ago
CVE-2026-39776
Editor Remote Code Execution (RCE) in Tabs <= 2.5 versions.
HIGH??????????NVD1 day ago
CVE-2026-39775
Subscriber Privilege Escalation in JobZilla - Job Board WordPress Theme <= 2.2 versions.
HIGH??????????NVD1 day ago
CVE-2026-39774
Unauthenticated Privilege Escalation in Tourfic Pro <= 1.17.3 versions.
HIGH??????????NVD1 day ago
CVE-2026-39773
Unauthenticated Privilege Escalation in Doctreat Core <= 1.7.0 versions.
CRITICAL??????????NVD1 day ago
CVE-2026-39772
Unauthenticated Bypass Vulnerability in Captcha by BestWebSoft <= 5.2.8 versions.
MEDIUM??????????NVD1 day ago
CVE-2026-39771
Subscriber SQL Injection in Buddyboss Platform <= 3.1.0 versions.
HIGH??????????NVD1 day ago
CVE-2026-39770
Unauthenticated Arbitrary File Upload in Doctreat <= 1.7.0 versions.
CRITICAL??????????NVD1 day ago
CVE-2026-39769
Unauthenticated Broken Authentication in Graphina <= 3.1.12 versions.
HIGH??????????NVD1 day ago
CVE-2026-39768
Unauthenticated Cross Site Scripting (XSS) in Security & Malware scan by CleanTalk <= 2.189 versions.
HIGH??????????NVD1 day ago
CVE-2026-39767
Subscriber Denial of Service Attack in WPBase Cache <= 5.5.6 versions.
MEDIUM??????????NVD1 day ago
CVE-2026-39766
Unauthenticated Cross Site Scripting (XSS) in ARForms <= 7.1.2 versions.
HIGH??????????NVD1 day ago
CVE-2026-39765
Shop Manager Privilege Escalation in Challan <= 3.7.88 versions.
HIGH??????????NVD1 day ago
CVE-2026-39764
Unauthenticated SQL Injection in Radius Booking — Booking Calendar for Appointments & Services <= 1.0.19 versions.
CRITICAL??????????NVD1 day ago
CVE-2026-39762
Missing Authorization vulnerability in Patterns In The Cloud Autoship Cloud for WooCommerce Subscription Products autoship-cloud allows Exploiting Inc...
MEDIUM??????????NVD1 day ago
CVE-2026-39761
Unauthenticated Privilege Escalation in Meta Box AIO <= 3.7.1 versions.
CRITICAL??????????NVD1 day ago
CVE-2026-39759
Employer / Sales Representative Arbitrary File Upload in Workreap Core <= 3.4.5 versions.
CRITICAL??????????NVD1 day ago
CVE-2026-39758
Unauthenticated Cross Site Scripting (XSS) in Midtrans-WooCommerce <= 2.32.3 versions.
HIGH??????????NVD1 day ago
🎁7-Day Free Trial — Try Pro or Team, no card required.
📧Email Delivery — Threat intel straight to your inbox.
♾️Unlimited Vendors — Track your entire stack.
🚨All New CVEs — Be the first to know.
📈EPSS Spike Alerts — Catch rising risk before it peaks.
🎯Custom EPSS/CVSS — Filter noise, focus on risk.
🛡️Exploit Intel — A 2nd confirmed-exploit signal beyond KEV.
🐙GitHub Issues — Auto-tracked, no duplicates.
📬Weekly Digest — One clean summary, not inbox spam.
🏷️Watchlist Groups — Tag alerts by team (Infra/AppSec/SOC).
💬Webhooks — Slack & Teams integration.
🔀Smart Routing — Critical alerts to one channel, rest to another.
🚫Ad-Free — Uninterrupted experience.
🎁7-Day Free Trial — Try Pro or Team, no card required.
📧Email Delivery — Threat intel straight to your inbox.
♾️Unlimited Vendors — Track your entire stack.
🚨All New CVEs — Be the first to know.
📈EPSS Spike Alerts — Catch rising risk before it peaks.
🎯Custom EPSS/CVSS — Filter noise, focus on risk.
🛡️Exploit Intel — A 2nd confirmed-exploit signal beyond KEV.
🐙GitHub Issues — Auto-tracked, no duplicates.
📬Weekly Digest — One clean summary, not inbox spam.
🏷️Watchlist Groups — Tag alerts by team (Infra/AppSec/SOC).
💬Webhooks — Slack & Teams integration.
🔀Smart Routing — Critical alerts to one channel, rest to another.
🚫Ad-Free — Uninterrupted experience.