Critical Alert 4 Active Exploits Detected Today

CVE-2026-33824 Microsoft Internet Key Exchange (IKE) Service Extensions Double Free Vulnerability →
CVE-2026-59310 Broadcom VMware vCenter Path Traversal Vulnerability →
CVE-2026-55040 Microsoft SharePoint Weak Authentication Vulnerability →
CVE-2026-65400 Apple macOS Improper Authentication Vulnerability →
Powered by CVE Watchtower
×
August 19, 2026

CVE Watchtower

Advanced Threat Data Export

Filter and download the raw CVE repository (CSV/JSON) for SIEM integration and internal reporting.

Data export is locked. Upgrade your package to enable filtering and downloading.

🔔 Premium Features
🔍 Filter Threats
Title
SeverityPoCActively ExploitedSourceDate
CVE-2026-67440
FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. In 1.3.2 and earlier, the DEVICE_BROWSE, DEVICE_NODE_ATTRIBUTE, HOST_INTERFA...
MEDIUM??????????NVD13 hours ago
CVE-2026-73103
No description available
UNKNOWN??????????NVD13 hours ago
CVE-2026-73112
No description available
UNKNOWN??????????NVD13 hours ago
CVE-2026-73111
No description available
UNKNOWN??????????NVD13 hours ago
CVE-2026-73106
No description available
UNKNOWN??????????NVD13 hours ago
CVE-2026-73105
No description available
UNKNOWN??????????NVD13 hours ago
CVE-2026-73104
No description available
UNKNOWN??????????NVD13 hours ago
CVE-2026-76032
Pydio Cells 5.0.0 through 5.0.2 returns share-link details to any authenticated user. The REST handler for GET /a/share/link/{Uuid} in idm/share/rest/...
MEDIUM??????????NVD14 hours ago
CVE-2026-49500
Dell Alienware Command Center (AWCC), versions prior to 6.14.20.0, contain an Improper Link Resolution Before File Access ('Link Following')...
MEDIUM??????????NVD14 hours ago
CVE-2026-75877
A flaw has been found in TRENDnet TV-IP751WIC 11.03.03. This vulnerability affects the function SystemNetworkChanged/SystemDDNSChanged/SystemEmailChan...
CRITICAL??????????NVD14 hours ago
CVE-2026-12520
The Sierra Wireless HL7800 cellular modem driver (drivers/modem/vendor_standalone/hl7800.c, located at drivers/modem/hl7800.c in v4.4.0 and earlier) p...
MEDIUM??????????NVD14 hours ago
CVE-2026-75936
Improper handling of highly compressed data in the GZIP auto-decompression handler in Amazon ion-java before 1.12.0 might allow remote actors to cause...
HIGH??????????NVD14 hours ago
CVE-2026-75935
Uncontrolled memory allocation in the binary Ion stream cursor in Amazon ion-java before 1.12.0 might allow remote actors to cause a denial of service...
HIGH??????????NVD14 hours ago
CVE-2026-75876
A security vulnerability has been detected in xianrendzw EasyReport up to 2.0.17.0522_Beta. Affected by this issue is some unknown functionality of th...
MEDIUM??????????NVD14 hours ago
CVE-2026-71417
Lemur manages TLS certificate creation. Prior to 1.9.3, POST /api/1/certificates/upload allowed a non-read-only user to create a duplicate row using a...
HIGH??????????NVD14 hours ago
CVE-2026-19671
Malcolm's upload-processing pipeline (scripts/safe-extract.py) enforces entry-count, nesting-depth, and total-uncompressed-byte limits when extra...
MEDIUM??????????NVD14 hours ago
CVE-2026-73529
Plainpad through 1.1.1, fixed in commit d3823fc, contains a missing rate limiting vulnerability that allows unauthenticated attackers to send unbounde...
MEDIUM??????????NVD14 hours ago
CVE-2026-71322
Lemur manages TLS certificate creation. Prior to 1.9.3, CertificateExport placed its CertificatePermission ownership check inside the plugin.requires_...
MEDIUM??????????NVD14 hours ago
CVE-2026-19670
Malcolm's nginx Lua role-based access control (RBAC) layer decides whether an authenticated user may reach a role-restricted path (e.g. /htadmin,...
MEDIUM??????????NVD14 hours ago
CVE-2026-71317
Lemur manages TLS certificate creation. Prior to 1.9.3, POST /api/1/authorities with type=subca did not require AuthorityPermission on the parent auth...
MEDIUM??????????NVD14 hours ago