CVE Watchtower

🔍 Filter Threats
🎁7-Day Free Trial — Try Pro or Team, no card required.
📧Email Delivery — Threat intel straight to your inbox.
♾️Unlimited Vendors — Track your entire stack.
🚨All New CVEs — Be the first to know.
📈EPSS Spike Alerts — Catch rising risk before it peaks.
🎯Custom EPSS/CVSS — Filter noise, focus on risk.
🛡️Exploit Intel — A 2nd confirmed-exploit signal beyond KEV.
🐙GitHub Issues — Auto-tracked, no duplicates.
📬Weekly Digest — One clean summary, not inbox spam.
🏷️Watchlist Groups — Tag alerts by team (Infra/AppSec/SOC).
💬Webhooks — Slack & Teams integration.
🔀Smart Routing — Critical alerts to one channel, rest to another.
🚫Ad-Free — Uninterrupted experience.
🎁7-Day Free Trial — Try Pro or Team, no card required.
📧Email Delivery — Threat intel straight to your inbox.
♾️Unlimited Vendors — Track your entire stack.
🚨All New CVEs — Be the first to know.
📈EPSS Spike Alerts — Catch rising risk before it peaks.
🎯Custom EPSS/CVSS — Filter noise, focus on risk.
🛡️Exploit Intel — A 2nd confirmed-exploit signal beyond KEV.
🐙GitHub Issues — Auto-tracked, no duplicates.
📬Weekly Digest — One clean summary, not inbox spam.
🏷️Watchlist Groups — Tag alerts by team (Infra/AppSec/SOC).
💬Webhooks — Slack & Teams integration.
🔀Smart Routing — Critical alerts to one channel, rest to another.
🚫Ad-Free — Uninterrupted experience.
Title
SeverityPoCActively ExploitedSourceDate
CVE-2026-105879
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetElements For Elementor j...
MEDIUM??????????NVD23 hours ago
CVE-2026-25434
Subscriber SQL Injection in WP2LEADS <= 3.5.7 versions.
HIGH??????????NVD23 hours ago
CVE-2026-25433
Subscriber Broken Access Control in WP2LEADS <= 3.5.7 versions.
HIGH??????????NVD23 hours ago
CVE-2026-105317
Subscriber SQL Injection in Paid Member Subscriptions <= 3.1.1 versions.
HIGH??????????NVD23 hours ago
CVE-2026-105071
Unauthenticated Sensitive Data Exposure in SiteVault – Backup, Restore, Migration & Cloning <= 1.5.17 versions.
HIGH??????????NVD23 hours ago
CVE-2026-105070
Unauthenticated Privilege Escalation in Salon booking system <= 10.31.7 versions.
HIGH??????????NVD23 hours ago
CVE-2026-105061
Unauthenticated Cross Site Scripting (XSS) in WP Mailster <= 1.9.0.0 versions.
HIGH??????????NVD23 hours ago
CVE-2026-105059
Subscriber Broken Access Control in Delete All Comments of wordpress <= 7.1 versions.
MEDIUM??????????NVD23 hours ago
CVE-2026-105058
Subscriber Privilege Escalation in WP User Profiles <= 2.7.3 versions.
HIGH??????????NVD23 hours ago
CVE-2026-105057
Unauthenticated Bypass Vulnerability in Zero Spam <= 5.7.11 versions.
MEDIUM??????????NVD23 hours ago
CVE-2026-104814
Unauthenticated Cross Site Scripting (XSS) in Form Block <= 1.8.1 versions.
HIGH??????????NVD23 hours ago
CVE-2026-104757
Editor Privilege Escalation in Import and export users and customers <= 2.5.5 versions.
HIGH??????????NVD23 hours ago
CVE-2026-104747
Unauthenticated PHP Object Injection in Haaken <= 1.5 versions.
HIGH??????????NVD23 hours ago
CVE-2026-104672
Unauthenticated Cross Site Scripting (XSS) in GiveWP <= 4.17.0 versions.
HIGH??????????NVD23 hours ago
CVE-2026-104670
Unauthenticated Cross Site Scripting (XSS) in LearnPress <= 4.4.9 versions.
HIGH??????????NVD23 hours ago
CVE-2026-104406
Unauthenticated Broken Access Control in picu <= 3.10.1 versions.
HIGH??????????NVD23 hours ago
CVE-2026-104405
Unauthenticated Privilege Escalation in GiveWP <= 4.17.0 versions.
HIGH??????????NVD23 hours ago
CVE-2026-104395
Unauthenticated Cross Site Scripting (XSS) in picu <= 3.10.1 versions.
HIGH??????????NVD23 hours ago
CVE-2026-104394
Unauthenticated Cross Site Scripting (XSS) in Charitable <= 1.8.12.3 versions.
HIGH??????????NVD23 hours ago
CVE-2026-104387
Unauthenticated Broken Access Control in PowerPress Podcasting <= 11.17.9 versions.
HIGH??????????NVD23 hours ago
🎁7-Day Free Trial — Try Pro or Team, no card required.
📧Email Delivery — Threat intel straight to your inbox.
♾️Unlimited Vendors — Track your entire stack.
🚨All New CVEs — Be the first to know.
📈EPSS Spike Alerts — Catch rising risk before it peaks.
🎯Custom EPSS/CVSS — Filter noise, focus on risk.
🛡️Exploit Intel — A 2nd confirmed-exploit signal beyond KEV.
🐙GitHub Issues — Auto-tracked, no duplicates.
📬Weekly Digest — One clean summary, not inbox spam.
🏷️Watchlist Groups — Tag alerts by team (Infra/AppSec/SOC).
💬Webhooks — Slack & Teams integration.
🔀Smart Routing — Critical alerts to one channel, rest to another.
🚫Ad-Free — Uninterrupted experience.
🎁7-Day Free Trial — Try Pro or Team, no card required.
📧Email Delivery — Threat intel straight to your inbox.
♾️Unlimited Vendors — Track your entire stack.
🚨All New CVEs — Be the first to know.
📈EPSS Spike Alerts — Catch rising risk before it peaks.
🎯Custom EPSS/CVSS — Filter noise, focus on risk.
🛡️Exploit Intel — A 2nd confirmed-exploit signal beyond KEV.
🐙GitHub Issues — Auto-tracked, no duplicates.
📬Weekly Digest — One clean summary, not inbox spam.
🏷️Watchlist Groups — Tag alerts by team (Infra/AppSec/SOC).
💬Webhooks — Slack & Teams integration.
🔀Smart Routing — Critical alerts to one channel, rest to another.
🚫Ad-Free — Uninterrupted experience.