Critical Alert 1 Active Exploit Detected Today

CVE-2026-64849 MLflow Server-Side Request Forgery Vulnerability →
Powered by CVE Watchtower
×
August 20, 2026

CVE Watchtower

Advanced Threat Data Export

Filter and download the raw CVE repository (CSV/JSON) for SIEM integration and internal reporting.

Data export is locked. Upgrade your package to enable filtering and downloading.

🔔 Premium Features
🔍 Filter Threats
Title
SeverityPoCActively ExploitedSourceDate
CVE-2026-54723
### Impact If the replication protocol is enabled by using the ``primary`` (or deprecated ``master``) role for a server instance, then the ``+changel...
MEDIUM??????????NVD1 day ago
CVE-2026-55224
## Path Traversal via Unsanitized Identifier in Plugin Install/Uninstall ### Summary The app-store plugin service concatenates unsanitized user-suppl...
HIGH??????????NVD1 day ago
CVE-2026-71675
An issue in Open5GS v.2.7.0 allows a remote attacker to cause a denial of service via the ngap_send_to_nas() function in src/amf/ngap-path.c
HIGH??????????NVD1 day ago
CVE-2026-71322
Lemur manages TLS certificate creation. Prior to 1.9.3, CertificateExport placed its CertificatePermission ownership check inside the plugin.requires_...
MEDIUM??????????NVD1 day ago
CVE-2026-71676
Buffer Overflow vulnerability in Open5GS v.2.7.0 allows a remote attacker to cause a denial of service via the NAS 5GS decoder chain, triggered when t...
HIGH??????????NVD1 day ago
CVE-2026-71317
Lemur manages TLS certificate creation. Prior to 1.9.3, POST /api/1/authorities with type=subca did not require AuthorityPermission on the parent auth...
MEDIUM??????????NVD1 day ago
CVE-2026-70666
Lemur manages TLS certificate creation. Prior to 1.9.3, an authority-role member could update acme_url through PUT /api/1/authorities/ without revalid...
HIGH??????????NVD1 day ago
CVE-2026-57826
An issue was discovered in openHiTLS 0.2.0 through 0.3.2. In the X.509 certificate chain verification, the basic constraints extension and CA flag pro...
CRITICAL??????????NVD1 day ago
CVE-2026-59915
Dell Alienware Command Center (AWCC), versions prior to 6.14.20.0, contain a Least Privilege Violation vulnerability. A low privileged attacker with l...
HIGH??????????NVD1 day ago
CVE-2026-52739
ZEBRA is a Zcash node written entirely in Rust. Prior to 4.5.0, a malicious block producer can terminate zebrad by placing the same shielded transacti...
MEDIUM??????????NVD1 day ago
CVE-2026-52734
ZEBRA is a Zcash node written entirely in Rust. Prior to 4.5.0, an unauthenticated P2P peer can cause the mempool download pipeline to retain transact...
MEDIUM??????????NVD1 day ago
CVE-2026-52481
An issue in SJRC F11 SJ-GPS-PRO firmware build 2019-09-17 allows a remote attacker to obtain sensitive information via the tcp_actions() function
HIGH??????????NVD1 day ago
CVE-2026-52480
An issue in SJRC F11 SJ-GPS-PRO firmware build 2019-09-17 allows a remote attacker to obtain sensitive information via the inetd service
MEDIUM??????????NVD1 day ago
CVE-2026-52733
ZEBRA is a Zcash node written entirely in Rust. Prior to 4.5.0, a natural or attacker-influenced chain fork can leave stale Sapling and Orchard note-c...
MEDIUM??????????NVD1 day ago
CVE-2026-47720
FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Prior to 1.3.2, the TDengine DAQ storage connector's escapeTdString fun...
MEDIUM??????????NVD1 day ago
CVE-2026-47721
FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Prior to 1.3.2, POST /api/scheduler and DELETE /api/scheduler in server/api/...
MEDIUM??????????NVD1 day ago
CVE-2026-12520
The Sierra Wireless HL7800 cellular modem driver (drivers/modem/vendor_standalone/hl7800.c, located at drivers/modem/hl7800.c in v4.4.0 and earlier) p...
MEDIUM??????????NVD1 day ago
CVE-2026-55211
### Impact Prior to version 0.0.19, surfio would not correctly validate size fields in irap files, leading to a buffer overflow . The severity rating ...
CRITICAL??????????NVD1 day ago
CVE-2026-55209
### Impact Prior to version 6.2.9 resdata would not correctly validate input in GRDECL files. The severity rating assumes that resdata is used to pars...
CRITICAL??????????NVD1 day ago
CVE-2026-55107
### Summary A guest mruby script running inside the Kobako sandbox can execute arbitrary Ruby in the host process, fully escaping the sandbox. ### De...
CRITICAL??????????NVD1 day ago