Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
CVE-2026-9830: CWE-287 Improper Authentication in bookingpress-appointment-booking-proCVE-2026-9830 0 The bookingpress-appointment-booking-pro WordPress plugin before 5.7.3 does not correctly invoke its REST permission callback, leaving every route in one of its API namespaces reachable without authentication and allowing unauthenticated attackers to read customer booking data and modify other users' bookings. Join the discussion | CVE Database V5 | 07/27/2026, 06:00:06 UTC Added: 07/27/2026, 06:22:59 UTC |
CVE-2026-14827: CWE-79 Cross-Site Scripting (XSS) in CalendarCVE-2026-14827 0 The Calendar WordPress plugin before 1.3.18 does not properly escape a user-supplied event field before outputting it inside an HTML attribute on a public-facing page, allowing users with the Contributor role to inject arbitrary JavaScript that executes in the browser of anyone viewing the calendar. Join the discussion | CVE Database V5 | 07/27/2026, 06:00:06 UTC Added: 07/27/2026, 06:22:59 UTC |
CVE-2026-14820: CWE-200 Information Exposure in Quiz and Survey Master (QSM)CVE-2026-14820 0 The Quiz and Survey Master (QSM) WordPress plugin before 11.1.3 does not implement rate limiting or standard failed-login auditing on its front-end credential-check functionality and returns distinct responses for valid and invalid accounts, allowing unauthenticated attackers to enumerate valid usernames and to brute-force passwords while bypassing brute-force protection Quiz and Survey Master (QSM) WordPress plugin before 11.1.3. Join the discussion | CVE Database V5 | 07/27/2026, 06:00:05 UTC Added: 07/27/2026, 06:22:59 UTC |
CVE-2026-14568: CWE-287 Improper Authentication in User Frontend: AI Powered Frontend Post Submission, User Directory, User Profile, Membership & User RegistrationCVE-2026-14568 0 The User Frontend: AI Powered Frontend Post Submission, User Directory, User Profile, Membership & User Registration WordPress plugin before 4.3.8 does not correctly verify ownership before deleting an attachment, allowing unauthenticated attackers to permanently delete author-less attachments such as guest uploads and User Frontend: AI Powered Frontend Post Submission, User Directory, User Profile, Membership & User Registration WordPress plugin before 4.3.8-installed placeholder media. Join the discussion | CVE Database V5 | 07/27/2026, 06:00:05 UTC Added: 07/27/2026, 06:22:57 UTC |
CVE-2026-14289: CWE-94 Improper Control of Generation of Code ('Code Injection') in FacturaONE para WooCommerce con VeriFactuCVE-2026-14289 0 The FacturaONE para WooCommerce con VeriFactu WordPress plugin before 5.37 does not authenticate one of its request handlers, whose only protection is derived from a cryptographic key that is empty in the default, unconfigured state, allowing unauthenticated attackers to write an arbitrary file into a web-accessible directory and achieve remote code execution. Join the discussion | CVE Database V5 | 07/27/2026, 06:00:05 UTC Added: 07/27/2026, 06:22:57 UTC |
CVE-2026-14236: CWE-601 URL Redirection to Untrusted Site ('Open Redirect') in Contact Form 7CVE-2026-14236 0 The Contact Form 7 WordPress plugin before 2.5 does not validate the host of a user-supplied return URL before using it as the success and cancel redirect targets of a Stripe checkout, allowing an unauthenticated attacker to redirect a victim, via a crafted link, to an arbitrary external site after the checkout flow. Join the discussion | CVE Database V5 | 07/27/2026, 06:00:05 UTC Added: 07/27/2026, 06:22:57 UTC |
CVE-2026-14235: CWE-284 Improper Access Control in Download ManagerCVE-2026-14235 0 The Download Manager WordPress plugin before 3.3.62 does not bind its temporary download token to the requesting session nor expire it promptly, making the token a long-lived, multi-use, portable bearer token, so that an attacker who obtains one leaked download key can repeatedly download a role- or password-protected package file without authorization. Join the discussion | CVE Database V5 | 07/27/2026, 06:00:04 UTC Added: 07/27/2026, 06:22:57 UTC |
CVE-2026-14203: CWE-79 Cross-Site Scripting (XSS) in Smart ManagerCVE-2026-14203 0 The Smart Manager WordPress plugin before 8.92.0 does not properly encode a post field before rendering it into an HTML attribute in its management grid, allowing users with the Contributor role or above to inject JavaScript that executes in the browser session of an administrator who views the grid. Join the discussion | CVE Database V5 | 07/27/2026, 06:00:04 UTC Added: 07/27/2026, 06:22:57 UTC |
CVE-2026-14190: CWE-79 Cross-Site Scripting (XSS) in Sina Extension for ElementorCVE-2026-14190 0 The Sina Extension for Elementor WordPress plugin before 3.10.2 does not escape a value reconstructed from request input in one of its unauthenticated AJAX handlers before reflecting it into the HTML response, allowing unauthenticated attackers to execute arbitrary JavaScript in the browser of anyone who triggers a crafted request. Join the discussion | CVE Database V5 | 07/27/2026, 06:00:04 UTC Added: 07/27/2026, 06:22:57 UTC |
CVE-2026-14189: CWE-89 SQL Injection in WPBotCVE-2026-14189 0 The WPBot WordPress plugin before 8.5.2 does not validate administrator-configured field identifiers before using them in a SQL query, allowing users with administrator access to perform SQL injection that executes when a visitor triggers a search. Join the discussion | CVE Database V5 | 07/27/2026, 06:00:04 UTC Added: 07/27/2026, 06:22:57 UTC |
Showing 1 to 10 of 67 results