Critical Alert 1 Active Exploit Detected Today

CVE-2026-45247 Mirasvit Full Page Cache Warmer Deserialization of Untrusted Data Vulnerability →
Powered by CVE Watchtower
×

CVE Watchtower

Advanced Threat Data Export

Filter and download the raw CVE repository (CSV/JSON) for SIEM integration and internal reporting.

Data export is locked. Upgrade your package to enable filtering and downloading.

πŸ”” Premium Features
πŸ” Filter Threats
Title
SeverityEPSS (30-Day)
PoCActively ExploitedSourceDate
CVE-2026-49367
In JetBrains IntelliJ IDEA before 2026.1.1 command execution was possible via the guest user account
HIGHπŸ”’ LOCKED??????????NVD5 days ago
CVE-2026-49366
In JetBrains IntelliJ IDEA before 2026.1.1 command injection was possible via filename completion
HIGHπŸ”’ LOCKED??????????NVD5 days ago
CVE-2026-47745
Shopper is a Headless e-commerce Admin Panel. Prior to 2.8.0, the admin tables for PaymentMethods, Currencies and Carriers exposed inline toggles and ...
MEDIUMπŸ”’ LOCKED??????????NVD5 days ago
CVE-2026-47744
Shopper is a Headless e-commerce Admin Panel. Prior to 2.8.0, two distinct authorization defects in the team settings allowed any authenticated panel ...
CRITICALπŸ”’ LOCKED??????????NVD5 days ago
CVE-2026-47742
Shopper is a Headless e-commerce Admin Panel. Prior to 2.8.0, Sub-form Livewire components used in the product editor (Edit, Inventory, Seo, Shipping,...
MEDIUMπŸ”’ LOCKED??????????NVD5 days ago
CVE-2026-47741
Shopper is a Headless e-commerce Admin Panel. Prior to 2.8.0, CreateOrderFromCartAction::execute previously created the Order row before checking and ...
MEDIUMπŸ”’ LOCKED??????????NVD5 days ago
CVE-2026-47740
Shopper is a Headless e-commerce Admin Panel. Prior to 2.8.0, Multiple Filament actions on the admin Order detail and Order shipments table were calla...
HIGHπŸ”’ LOCKED??????????NVD5 days ago
CVE-2026-46344
liboqs is a C-language cryptographic library that provides implementations of post-quantum cryptography algorithms. Prior to 0.16.0, an out-of-bounds ...
MEDIUMπŸ”’ LOCKED??????????NVD5 days ago
CVE-2026-46372
SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines, ...
HIGHπŸ”’ LOCKED??????????NVD5 days ago
CVE-2026-44518
liboqs is a C-language cryptographic library that provides implementations of post-quantum cryptography algorithms. Prior to 0.16.0, an out-of-bounds ...
MEDIUMπŸ”’ LOCKED??????????NVD5 days ago
CVE-2026-44648
SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines, ...
HIGHπŸ”’ LOCKED??????????NVD5 days ago
CVE-2026-44649
SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines, ...
CRITICALπŸ”’ LOCKED??????????NVD5 days ago
CVE-2026-44650
SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines, ...
CRITICALπŸ”’ LOCKED??????????NVD5 days ago
CVE-2026-38739
NB: All tags and branches in this repository are past their end of life, so the vulnerability will not be fixed. The advisory is posted on the request...
HIGHπŸ”’ LOCKED??????????NVD5 days ago
CVE-2026-46690
## Summary `Sender::send` in `src/lib.rs` contains an `unsafe` block in the `DISCONNECTED` arm that transmutes a **raw pointer** (`*mut Producer<T...
MEDIUMπŸ”’ LOCKED??????????NVD5 days ago
CVE-2026-47266
Formie is a Craft CMS plugin for creating forms. Prior to 2.2.21 and 3.1.26, unauthenticated users could modify existing submissions by posting a know...
UNKNOWNπŸ”’ LOCKED??????????NVD5 days ago
CVE-2026-34127
A stored cross-site scripting (XSS) vulnerability has been identified in the web management interface of TP-Link's TL-SG108PE v5 switch due to im...
UNKNOWNπŸ”’ LOCKED??????????NVD5 days ago
CVE-2026-48555
Spatie Laravel Media Library before version 11.23.0 contains a server-side request forgery vulnerability that allows remote attackers to cause the ser...
HIGHπŸ”’ LOCKED??????????NVD5 days ago
CVE-2026-4387
StrongDM Desktop Application before 23.74.0 (Desktop Client before 53.77.0) on Microsoft Windows stores authentication state, including a JSON Web Tok...
UNKNOWNπŸ”’ LOCKED??????????NVD5 days ago
CVE-2026-47190
### Impact IPAM is the IP address Manager for Cluster API Provider Metal3. The IPAM controller's ClusterRole granted full CRUD permissions (crea...
MEDIUMπŸ”’ LOCKED??????????NVD5 days ago