Critical Alert 1 Active Exploit Detected Today

CVE-2026-45247 Mirasvit Full Page Cache Warmer Deserialization of Untrusted Data Vulnerability →
Powered by CVE Watchtower
×

CVE Watchtower

Advanced Threat Data Export

Filter and download the raw CVE repository (CSV/JSON) for SIEM integration and internal reporting.

Data export is locked. Upgrade your package to enable filtering and downloading.

πŸ”” Premium Features
πŸ” Filter Threats
Title
SeverityEPSS (30-Day)
PoCActively ExploitedSourceDate
CVE-2026-45619
WWBN AVideo is an open source video platform. In 29.0 and earlier, EpgParser.php, plugin/AI/receiveAsync.json.php, and other locations do not use the ...
MEDIUMπŸ”’ LOCKED??????????NVD5 days ago
CVE-2026-44698
Home Assistant is open source home automation software that puts local control and privacy first. Prior to 2026.4.1 for iOS and 2026.4.4 for Android, ...
HIGHπŸ”’ LOCKED??????????NVD5 days ago
CVE-2026-10063
A vulnerability was identified in TRENDnet TEW-432BRP 3.10B20. Affected by this issue is the function formWPS of the file /goform/formWPS. Such manipu...
HIGHπŸ”’ LOCKED??????????NVD5 days ago
CVE-2026-10062
A vulnerability was determined in TRENDnet TEW-432BRP 3.10B20. Affected by this vulnerability is the function formSetRoute of the file /goform/formSet...
HIGHπŸ”’ LOCKED??????????NVD5 days ago
CVE-2026-40528
OpenSC before 0.27.0, fixed in commit 0358817, contains a stack and heap buffer overrun vulnerability in the do_key_value() function in src/pkcs15init...
LOWπŸ”’ LOCKED??????????NVD5 days ago
CVE-2026-10061
A vulnerability was found in TRENDnet TEW-432BRP 3.10B20. Affected is the function formWPS of the file /goform/formWPS. The manipulation of the argume...
MEDIUMπŸ”’ LOCKED??????????NVD5 days ago
CVE-2026-40510
OpenSC before 0.27.0-rc1, fixed in commit 3f24f0b, contains a stack buffer overflow vulnerability in piv_process_history() in src/libopensc/card-piv.c...
LOWπŸ”’ LOCKED??????????NVD5 days ago
CVE-2026-49318
Incorrect behavior order in the Infotainment / Digital Round display of the Indian Motorcycle Scout Bobber + Tech 2025 model year allows an adjacent-n...
LOWπŸ”’ LOCKED??????????NVD5 days ago
CVE-2026-48527
HAX CMS helps manage microsite universe with PHP or NodeJs backends. Versions up to and including 26.0.0 are affected by a stored cross-site scripting...
HIGHπŸ”’ LOCKED??????????NVD5 days ago
CVE-2026-45611
Rejected reason: Further research determined the issue is not a vulnerability.
UNKNOWNπŸ”’ LOCKED??????????NVD5 days ago
CVE-2026-45312
RAGFlow is an open-source RAG (Retrieval-Augmented Generation) engine. In 0.24.0 and earlier, a Jinja2 template injection in the prompt generator (rag...
CRITICALπŸ”’ LOCKED??????????NVD5 days ago
CVE-2026-10060
A vulnerability has been found in TRENDnet TEW-432BRP 3.10B20. This impacts the function formSetRoute of the file /goform/formSetRoute. The manipulati...
MEDIUMπŸ”’ LOCKED??????????NVD5 days ago
CVE-2026-47696
WWBN AVideo is an open source video platform. In 29.0 and earlier, plugin/AuthorizeNet/processPayment.json.php credits the logged-in user's walle...
UNKNOWNπŸ”’ LOCKED??????????NVD5 days ago
CVE-2026-10075
DreamMaker developed by Interinfo has a Path Traversal vulnerability, allowing unauthenticated remote attackers to read file names under arbitrary pat...
MEDIUMπŸ”’ LOCKED??????????NVD5 days ago
CVE-2026-44237
FreePBX is an open source IP PBX. Prior to 17.0.8, the FreePBX api module's OAuth2 implementation does not sufficiently validate client credentia...
UNKNOWNπŸ”’ LOCKED??????????NVD5 days ago
CVE-2026-10074
DreamMaker developed by Interinfo has an Arbitrary File Read vulnerability, allowing privileged local attackers to exploit Relative Path Traversal to ...
MEDIUMπŸ”’ LOCKED??????????NVD5 days ago
CVE-2026-44238
FreePBX is an open source IP PBX. Prior to 16.0.50 and 17.0.11, the CDR Reports module page allows SQL injection through the order and sort POST param...
UNKNOWNπŸ”’ LOCKED??????????NVD5 days ago
CVE-2026-44239
FreePBX is an open source IP PBX. Prior to 16.0.22 and 17.0.5, the Dashboard module's getcontent AJAX handler includes PHP files based on user-su...
UNKNOWNπŸ”’ LOCKED??????????NVD5 days ago
CVE-2026-49317
Incorrect behavior order in the Infotainment / Digital Round display of the Indian Motorcycle Scout Bobber + Tech 2025 model year allows an adjacent-n...
LOWπŸ”’ LOCKED??????????NVD5 days ago
CVE-2026-46376
FreePBX is an open source IP PBX. From 15.0.42 to before 16.0.45 and 17.0.7, unauthenticated users may be able to access the User Control Panel (UCP) ...
UNKNOWNπŸ”’ LOCKED??????????NVD5 days ago