CVE Watchtower

🔍 Filter Threats
🎁7-Day Free Trial — Try Pro or Team, no card required.
📧Email Delivery — Threat intel straight to your inbox.
♾️Unlimited Vendors — Track your entire stack.
🚨All New CVEs — Be the first to know.
📈EPSS Spike Alerts — Catch rising risk before it peaks.
🎯Custom EPSS/CVSS — Filter noise, focus on risk.
🛡️Exploit Intel — A 2nd confirmed-exploit signal beyond KEV.
🐙GitHub Issues — Auto-tracked, no duplicates.
📬Weekly Digest — One clean summary, not inbox spam.
🏷️Watchlist Groups — Tag alerts by team (Infra/AppSec/SOC).
💬Webhooks — Slack & Teams integration.
🔀Smart Routing — Critical alerts to one channel, rest to another.
🚫Ad-Free — Uninterrupted experience.
🎁7-Day Free Trial — Try Pro or Team, no card required.
📧Email Delivery — Threat intel straight to your inbox.
♾️Unlimited Vendors — Track your entire stack.
🚨All New CVEs — Be the first to know.
📈EPSS Spike Alerts — Catch rising risk before it peaks.
🎯Custom EPSS/CVSS — Filter noise, focus on risk.
🛡️Exploit Intel — A 2nd confirmed-exploit signal beyond KEV.
🐙GitHub Issues — Auto-tracked, no duplicates.
📬Weekly Digest — One clean summary, not inbox spam.
🏷️Watchlist Groups — Tag alerts by team (Infra/AppSec/SOC).
💬Webhooks — Slack & Teams integration.
🔀Smart Routing — Critical alerts to one channel, rest to another.
🚫Ad-Free — Uninterrupted experience.
Title
SeverityPoCActively ExploitedSourceDate
CVE-2026-39727
Subscriber Cross Site Scripting (XSS) in WC Fields Factory <= 4.1.12 versions.
MEDIUM??????????NVD22 hours ago
CVE-2026-39726
Unauthenticated Cross Site Scripting (XSS) in Lumise Product Designer <= 2.1.1 versions.
HIGH??????????NVD22 hours ago
CVE-2026-39725
Contributor Remote Code Execution (RCE) in Content Visibility for Divi Builder <= 5.03 versions.
HIGH??????????NVD22 hours ago
CVE-2026-39724
Unauthenticated Cross Site Scripting (XSS) in HTTP Requests Manager <= 1.3.11 versions.
HIGH??????????NVD22 hours ago
CVE-2026-39722
Unauthenticated Cross Site Scripting (XSS) in WPLMS <= 4.972 versions.
HIGH??????????NVD22 hours ago
CVE-2026-39720
Unauthenticated Cross Site Scripting (XSS) in Mapster WP Maps <= 2.0.4 versions.
HIGH??????????NVD22 hours ago
CVE-2026-39719
Unauthenticated Server Side Request Forgery (SSRF) in PDF Smart Viewer for Elementor <= 1.0.4 versions.
HIGH??????????NVD22 hours ago
CVE-2026-32581
Subscriber SQL Injection in Mooberry Book Manager 4.16.2 versions.
HIGH??????????NVD22 hours ago
CVE-2026-32580
Unauthenticated SQL Injection in WooCommerce Lottery <= 2.2.9 versions.
HIGH??????????NVD22 hours ago
CVE-2026-32579
Unauthenticated Arbitrary File Upload in Kognetiks Chatbot for WordPress <= 2.4.9 versions.
CRITICAL??????????NVD22 hours ago
CVE-2026-32578
Subscriber Broken Access Control in ECPay Ecommerce for WooCommerce <= 1.1.2606090 versions.
HIGH??????????NVD22 hours ago
CVE-2026-32577
Unauthenticated Cross Site Scripting (XSS) in Frontend File Manager <= 23.6 versions.
HIGH??????????NVD22 hours ago
CVE-2026-32575
Unauthenticated Cross Site Scripting (XSS) in SUMO Affiliates Pro <= 11.7.0 versions.
HIGH??????????NVD22 hours ago
CVE-2026-32574
Unauthenticated Cross Site Scripting (XSS) in Smart Forms <= 2.6.104 versions.
HIGH??????????NVD22 hours ago
CVE-2026-32572
Unauthenticated Cross Site Scripting (XSS) in WP User Frontend Pro <= 4.2.13 versions.
HIGH??????????NVD22 hours ago
CVE-2026-32571
Subscriber Cross Site Scripting (XSS) in Ohio Extra <= 3.6.8 versions.
MEDIUM??????????NVD22 hours ago
CVE-2026-32570
Unauthenticated Cross Site Scripting (XSS) in Progressify - Progressive Web App (PWA) <= 1.6.0 versions.
HIGH??????????NVD22 hours ago
CVE-2026-32569
Unauthenticated Cross Site Scripting (XSS) in WP Media folder <= 6.2.2 versions.
HIGH??????????NVD22 hours ago
CVE-2026-32568
Subscriber Remote Code Execution (RCE) in WooCommerce Designer Pro <= 1.9.33 versions.
CRITICAL??????????NVD22 hours ago
CVE-2026-32557
Unauthenticated SQL Injection in WooCommerce Appointments <= 5.3.2 versions.
CRITICAL??????????NVD22 hours ago
🎁7-Day Free Trial — Try Pro or Team, no card required.
📧Email Delivery — Threat intel straight to your inbox.
♾️Unlimited Vendors — Track your entire stack.
🚨All New CVEs — Be the first to know.
📈EPSS Spike Alerts — Catch rising risk before it peaks.
🎯Custom EPSS/CVSS — Filter noise, focus on risk.
🛡️Exploit Intel — A 2nd confirmed-exploit signal beyond KEV.
🐙GitHub Issues — Auto-tracked, no duplicates.
📬Weekly Digest — One clean summary, not inbox spam.
🏷️Watchlist Groups — Tag alerts by team (Infra/AppSec/SOC).
💬Webhooks — Slack & Teams integration.
🔀Smart Routing — Critical alerts to one channel, rest to another.
🚫Ad-Free — Uninterrupted experience.
🎁7-Day Free Trial — Try Pro or Team, no card required.
📧Email Delivery — Threat intel straight to your inbox.
♾️Unlimited Vendors — Track your entire stack.
🚨All New CVEs — Be the first to know.
📈EPSS Spike Alerts — Catch rising risk before it peaks.
🎯Custom EPSS/CVSS — Filter noise, focus on risk.
🛡️Exploit Intel — A 2nd confirmed-exploit signal beyond KEV.
🐙GitHub Issues — Auto-tracked, no duplicates.
📬Weekly Digest — One clean summary, not inbox spam.
🏷️Watchlist Groups — Tag alerts by team (Infra/AppSec/SOC).
💬Webhooks — Slack & Teams integration.
🔀Smart Routing — Critical alerts to one channel, rest to another.
🚫Ad-Free — Uninterrupted experience.