Critical Alert 1 Active Exploit Detected Today

CVE-2026-45247 Mirasvit Full Page Cache Warmer Deserialization of Untrusted Data Vulnerability →
Powered by CVE Watchtower
×

CVE Watchtower

Advanced Threat Data Export

Filter and download the raw CVE repository (CSV/JSON) for SIEM integration and internal reporting.

Data export is locked. Upgrade your package to enable filtering and downloading.

πŸ”” Premium Features
πŸ” Filter Threats
Title
SeverityEPSS (30-Day)
PoCActively ExploitedSourceDate
CVE-2018-25395
Kados R10 GreenBee contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicio...
HIGHπŸ”’ LOCKED??????????NVD5 days ago
CVE-2018-25394
Kados R10 GreenBee contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicio...
HIGHπŸ”’ LOCKED??????????NVD5 days ago
CVE-2018-25393
Navigate CMS 2.8.5 contains a path traversal vulnerability that allows authenticated users to download arbitrary files by injecting directory traversa...
MEDIUMπŸ”’ LOCKED??????????NVD5 days ago
CVE-2018-25392
MaxOn ERP Software 8.x-9.x contains an SQL injection vulnerability that allows authenticated users to execute arbitrary SQL queries through the nomor,...
HIGHπŸ”’ LOCKED??????????NVD5 days ago
CVE-2018-25391
HaPe PKH 1.1 fails to enforce authorization on its record deletion endpoints, allowing unauthenticated attackers to delete arbitrary records by sendin...
HIGHπŸ”’ LOCKED??????????NVD5 days ago
CVE-2018-25390
HaPe PKH 1.1 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code throug...
HIGHπŸ”’ LOCKED??????????NVD5 days ago
CVE-2018-25389
HaPe PKH 1.1 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code throug...
HIGHπŸ”’ LOCKED??????????NVD5 days ago
CVE-2018-25388
HaPe PKH 1.1 contains an arbitrary file upload vulnerability that allows authenticated attackers to upload malicious files by bypassing file type vali...
HIGHπŸ”’ LOCKED??????????NVD5 days ago
CVE-2018-25387
HaPe PKH 1.1 contains a cross-site request forgery vulnerability that allows attackers to change administrator passwords by submitting forged requests...
MEDIUMπŸ”’ LOCKED??????????NVD5 days ago
CVE-2018-25386
HaPe PKH 1.1 contains multiple SQL injection vulnerabilities in admin/media.php that allow attackers to manipulate database queries by injecting SQL c...
HIGHπŸ”’ LOCKED??????????NVD5 days ago
CVE-2018-25385
E-Registrasi Pencak Silat 18.10 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by inje...
HIGHπŸ”’ LOCKED??????????NVD5 days ago
CVE-2018-25384
Wikidforum 2.20 contains a cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts by submitting crafted HT...
MEDIUMπŸ”’ LOCKED??????????NVD5 days ago
CVE-2018-25383
Free MP3 CD Ripper 2.8 contains a stack-based buffer overflow vulnerability in WMA file processing that allows local attackers to bypass DEP protectio...
HIGHπŸ”’ LOCKED??????????NVD5 days ago
CVE-2018-25382
Zechat 1.5 contains an SQL injection vulnerability that allows unauthenticated attackers to extract database information by injecting SQL code through...
HIGHπŸ”’ LOCKED??????????NVD5 days ago
CVE-2026-10064
A security flaw has been discovered in TRENDnet TEW-432BRP 3.10B20. This affects the function formSetPortTr of the file /goform/formSetPortTr. Perform...
MEDIUMπŸ”’ LOCKED??????????NVD5 days ago
CVE-2026-10042
manga-image-translator contains a remote code execution vulnerability in the shared API server mode due to unsafe deserialization of untrusted pickle ...
CRITICALπŸ”’ LOCKED??????????NVD5 days ago
CVE-2026-47694
WWBN AVideo is an open source video platform. In 29.0 and earlier, AVideo stores category descriptions from user input and later renders category_desc...
MEDIUMπŸ”’ LOCKED??????????NVD5 days ago
CVE-2026-45707
n8n-MCP is an MCP server that provides AI assistants access to n8n node documentation, properties, and operations. Prior to 2.51.2, when ENABLE_MULTI_...
HIGHπŸ”’ LOCKED??????????NVD5 days ago
CVE-2026-45620
WWBN AVideo is an open source video platform. In 29.0 and earlier, objects/mention.json.php has no User::loginCheck() or admin gate. It only has an en...
MEDIUMπŸ”’ LOCKED??????????NVD5 days ago
CVE-2026-46510
form-data-objectizer converts FormData to object. Prior to 1.0.1, form-data-objectizer walks bracket-notation form keys (e.g. name[sub]) into nested o...
HIGHπŸ”’ LOCKED??????????NVD5 days ago