Skip to main content

Live Threat Intelligence Radar

Real-time global cyber threat intelligence and monitoring

Geographic Threat Distribution

Heat map of affected countries

Full map →
Threat density
037447
132 countries affected

Live Threat Feed

Real-time updates

LIVE

Threat Timeline

Trend analysis over time

Drag to select a custom date range
Hover over data points to see details • Click points to view threats for that date • Drag to zoom into a time period
Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

View Plans & PricingCompare all plans

API access activates after upgrading in Console -> Billing.

Custom feeds

Build private feeds with layered filters and curated intel views.

Automations + integrations

Email alerts, webhooks, Slack, and routes into SIEMs or MISPs.

API access (baseline limits)

Unlock API v1 access; subscriptions increase rate limits.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
threat-finder — Open SourceFREE CLI

Scan your servers for these threats

One command matches your running services against Radar by exact package (purl/CPE), with distro-backport-aware version checks. Bring your API key.

Get it on GitHub

Threat Intelligence Database

Comprehensive database with detailed analysis

View all →
Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Last 30 days

CVE-2026-103685 is a missing authorization vulnerability in the VillaTheme ALD – Dropshipping and Fulfillment for AliExpress and WooCommerce plugin. It affects versions from the initial release up to 2.2.4. The flaw allows exploitation of incorrectly configured access control security levels, potentially leading to unauthorized actions. The vulnerability has a medium severity rating with a CVSS score of 4.3. No official patch or remediation information is provided in the available data.

Join the discussion

TabularisDB's tabularis component up to version 0.27.0 has an incorrect authorization vulnerability in the MCP run_query safety gate. This flaw allows untrusted or prompt-injected MCP clients to bypass read-only restrictions by submitting SELECT statements that cause side effects, such as data modification. Attackers can exploit this to run PostgreSQL functions embedding data-altering commands without approval prompts.

Join the discussion

slide-maker versions up to 5.8.0 contain a path traversal vulnerability in the generate_images_openai.py component. This flaw allows attackers to write image files outside the intended output directory by using specially crafted filenames in the image prompt manifest. By including ../ sequences or symlinked filenames, attackers can create directories or overwrite files at arbitrary filesystem locations.

Join the discussion

CVE-2026-27350 is a Server-Side Request Forgery (SSRF) vulnerability in Builderius.io Builderius affecting versions from 1.4 through 1.4-beta. The vulnerability allows an attacker to induce the server to make unintended requests, potentially leading to information disclosure and integrity impacts. The CVSS v3.1 score is 7.2, indicating a high severity level. No official patch or vendor advisory is provided, and no known exploits are reported in the wild.

Join the discussion

CVE-2026-97853 is a memory allocation vulnerability in the ericmj decimal library affecting versions from 0.1.0 up to but not including 3.1.2. The Decimal.round/3 function can allocate excessive memory when given a large 'places' argument, potentially leading to denial of service by exhausting system memory and crashing the BEAM VM. This occurs because the function builds a large charlist of zero digits proportional to the 'places' argument before applying context precision. Applications that allow unbounded user input for the number of decimal places are vulnerable.

Join the discussion

CVE-2026-66480 is a medium severity vulnerability in YITH WooCommerce Product Add-Ons that allows unauthorized retrieval of embedded sensitive system information. It affects versions up to and including 4.34.0. The vulnerability does not require privileges or user interaction to exploit and has a network attack vector. No known exploits are reported in the wild, and no official patch or remediation details are currently provided.

Join the discussion

CVE-2026-57742 is a reflected cross-site scripting (XSS) vulnerability in ThemeREX Group's Kids Planet product. It allows improper neutralization of input during web page generation, leading to potential injection of malicious scripts. The vulnerability affects versions up to 2.2.14.2. The CVSS score is 7.1, indicating a high severity level. No patch or remediation information is provided in the available data.

Join the discussion

CVE-2026-107434 is a medium severity vulnerability in videowhisper MicroPayments versions up to 3.2.9. It involves improper validation of specified quantity in input, classified under CWE-1284. This flaw allows a subscriber bypass, potentially impacting integrity and availability without affecting confidentiality.

Join the discussion

CVE-2026-107420 is an unauthenticated bypass vulnerability in the Pay With MetaMask For WooCommerce – Cryptocurrency Payment Gateway plugin, affecting versions up to 1.7.2. The flaw relates to insufficient verification of data authenticity (CWE-345), allowing an attacker to bypass certain authentication checks without privileges. The vulnerability has a CVSS 3.1 base score of 5.3 (medium severity), indicating limited impact on integrity but no confidentiality or availability loss. No patch or remediation information is currently available from the vendor. There are no known exploits in the wild at this time.

Join the discussion

CVE-2026-81797 is a critical vulnerability in the ThemeRex Buzz Stone | Magazine & Viral Blog WordPress Theme versions up to 1.0.2. It involves unauthenticated PHP object injection due to deserialization of untrusted data, which can lead to full compromise of confidentiality, integrity, and availability of the affected system.

Join the discussion

Showing 1 to 10 of 17907 results

Page 1 of 1791
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses