Live Threat Intelligence Radar
Real-time global cyber threat intelligence and monitoring
Geographic Threat Distribution
Heat map of affected countries
Live Threat Feed
Real-time updates
Threat Timeline
Trend analysis over time
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds
Build private feeds with layered filters and curated intel views.
Automations + integrations
Email alerts, webhooks, Slack, and routes into SIEMs or MISPs.
API access (baseline limits)
Unlock API v1 access; subscriptions increase rate limits.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Scan your servers for these threats
One command matches your running services against Radar by exact package (purl/CPE), with distro-backport-aware version checks. Bring your API key.
Threat Intelligence Database
Comprehensive database with detailed analysis
0 CVE-2026-103685 is a missing authorization vulnerability in the VillaTheme ALD – Dropshipping and Fulfillment for AliExpress and WooCommerce plugin. It affects versions from the initial release up to 2.2.4. The flaw allows exploitation of incorrectly configured access control security levels, potentially leading to unauthorized actions. The vulnerability has a medium severity rating with a CVSS score of 4.3. No official patch or remediation information is provided in the available data. Join the discussion | CVE Database V5 | 10/10/2026, 19:55:52 UTC Added: 10/10/2026, 20:04:06 UTC |
TabularisDB's tabularis component up to version 0.27.0 has an incorrect authorization vulnerability in the MCP run_query safety gate. This flaw allows untrusted or prompt-injected MCP clients to bypass read-only restrictions by submitting SELECT statements that cause side effects, such as data modification. Attackers can exploit this to run PostgreSQL functions embedding data-altering commands without approval prompts. Join the discussion | CVE Database V5 | 10/10/2026, 19:54:37 UTC Added: 10/10/2026, 20:04:06 UTC |
0 slide-maker versions up to 5.8.0 contain a path traversal vulnerability in the generate_images_openai.py component. This flaw allows attackers to write image files outside the intended output directory by using specially crafted filenames in the image prompt manifest. By including ../ sequences or symlinked filenames, attackers can create directories or overwrite files at arbitrary filesystem locations. Join the discussion | CVE Database V5 | 10/10/2026, 19:54:36 UTC Added: 10/10/2026, 20:04:06 UTC |
0 CVE-2026-27350 is a Server-Side Request Forgery (SSRF) vulnerability in Builderius.io Builderius affecting versions from 1.4 through 1.4-beta. The vulnerability allows an attacker to induce the server to make unintended requests, potentially leading to information disclosure and integrity impacts. The CVSS v3.1 score is 7.2, indicating a high severity level. No official patch or vendor advisory is provided, and no known exploits are reported in the wild. Join the discussion | CVE Database V5 | 10/10/2026, 19:44:36 UTC Added: 10/10/2026, 20:04:06 UTC |
0 CVE-2026-97853 is a memory allocation vulnerability in the ericmj decimal library affecting versions from 0.1.0 up to but not including 3.1.2. The Decimal.round/3 function can allocate excessive memory when given a large 'places' argument, potentially leading to denial of service by exhausting system memory and crashing the BEAM VM. This occurs because the function builds a large charlist of zero digits proportional to the 'places' argument before applying context precision. Applications that allow unbounded user input for the number of decimal places are vulnerable. Join the discussion | CVE Database V5 | 10/10/2026, 19:43:45 UTC Added: 10/10/2026, 20:04:06 UTC |
CVE-2026-66480 is a medium severity vulnerability in YITH WooCommerce Product Add-Ons that allows unauthorized retrieval of embedded sensitive system information. It affects versions up to and including 4.34.0. The vulnerability does not require privileges or user interaction to exploit and has a network attack vector. No known exploits are reported in the wild, and no official patch or remediation details are currently provided. Join the discussion | CVE Database V5 | 10/10/2026, 19:42:40 UTC Added: 10/10/2026, 19:49:19 UTC |
CVE-2026-57742 is a reflected cross-site scripting (XSS) vulnerability in ThemeREX Group's Kids Planet product. It allows improper neutralization of input during web page generation, leading to potential injection of malicious scripts. The vulnerability affects versions up to 2.2.14.2. The CVSS score is 7.1, indicating a high severity level. No patch or remediation information is provided in the available data. Join the discussion | CVE Database V5 | 10/10/2026, 19:40:34 UTC Added: 10/10/2026, 19:49:06 UTC |
0 CVE-2026-107434 is a medium severity vulnerability in videowhisper MicroPayments versions up to 3.2.9. It involves improper validation of specified quantity in input, classified under CWE-1284. This flaw allows a subscriber bypass, potentially impacting integrity and availability without affecting confidentiality. Join the discussion | CVE Database V5 | 10/10/2026, 19:36:24 UTC Added: 10/10/2026, 19:49:00 UTC |
CVE-2026-107420 is an unauthenticated bypass vulnerability in the Pay With MetaMask For WooCommerce – Cryptocurrency Payment Gateway plugin, affecting versions up to 1.7.2. The flaw relates to insufficient verification of data authenticity (CWE-345), allowing an attacker to bypass certain authentication checks without privileges. The vulnerability has a CVSS 3.1 base score of 5.3 (medium severity), indicating limited impact on integrity but no confidentiality or availability loss. No patch or remediation information is currently available from the vendor. There are no known exploits in the wild at this time. Join the discussion | CVE Database V5 | 10/10/2026, 19:36:23 UTC Added: 10/10/2026, 19:49:00 UTC |
0 CVE-2026-81797 is a critical vulnerability in the ThemeRex Buzz Stone | Magazine & Viral Blog WordPress Theme versions up to 1.0.2. It involves unauthenticated PHP object injection due to deserialization of untrusted data, which can lead to full compromise of confidentiality, integrity, and availability of the affected system. Join the discussion | CVE Database V5 | 10/10/2026, 19:36:20 UTC Added: 10/10/2026, 19:49:23 UTC |
Showing 1 to 10 of 17907 results