Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

ISC Stormcast For Thursday, September 10th, 2026 https://isc.sans.edu/podcastdetail/10088, (Thu, Sep 10th)
0

This entry is a daily security news update from the SANS Internet Storm Center (ISC) titled 'ISC Stormcast For Thursday, September 10th, 2026.' It provides general information and links to a podcast and classes but does not describe any specific security threat or vulnerability.

LowNews
Join the discussion
CVE-2026-87803: Countly DBViewer authorization bypass via nested aggregation stage poisoning in Countly countly-serverCVE-2026-87803
0

CVE-2026-87803 is an authorization bypass vulnerability in the Countly Server DBViewer component. It arises from improper detection of nested aggregation stages in the aggregation stage sanitizer. This flaw allows a non-admin user with DBViewer read permission to inject forbidden MongoDB operators, enabling unauthorized cross-collection data access, including sensitive information like password-reset tokens.

Join the discussion
CVE-2026-78303: CWE-201: Insertion of Sensitive Information Into Sent Data in joomshaper.com SP Property extension for JoomlaCVE-2026-78303
0

CVE-2026-78303 is a medium severity vulnerability in the SP Property extension for Joomla by joomshaper.com. Versions 1.0.0 through 4.1.3 are affected. The issue involves unvalidated email destination and form manipulation in booking requests, where the recipient routing relied on client-submitted hidden fields. This could allow insertion of sensitive information into sent data.

Join the discussion
CVE-2026-78374: CWE-201: Insertion of Sensitive Information Into Sent Data in joomlart.com T4 Page Builder extension for JoomlaCVE-2026-78374
0

The T4 Page Builder extension for Joomla versions 1.0.0 through 2.2.0 contains a vulnerability that allows unauthenticated attackers to send emails via an open mail relay through the front-end JSON editor's contact AJAX endpoint. This endpoint lacks authentication, CSRF protection, captcha enforcement (if no captcha plugin is enabled), and rate limiting, enabling attackers to control the recipient, subject, and HTML body of the email, which is sent from the site's configured sender identity.

Join the discussion
CVE-2026-78302: CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in joomshaper.com SP Property extension for JoomlaCVE-2026-78302
0

CVE-2026-78302 is a high-severity stored cross-site scripting (XSS) vulnerability in the SP Property extension for Joomla by joomshaper.com. Versions 1.0.0 through 4.1.3 are affected. The vulnerability arises from multiple template files in frontend views and administrator list tables that render attributes and text values directly into HTML without proper contextual escaping, allowing unauthenticated attackers to inject malicious scripts.

Join the discussion
CVE-2026-78084: CWE-284 Improper Access Control in joomshaper.com SP Property extension for JoomlaCVE-2026-78084
0

A vulnerability in the SP Property extension for Joomla versions 1.0.0 through 4.1.3 allows unauthorized users to perform gallery image management actions without proper access control or CSRF protection. This flaw enables file removal with arbitrary paths and uploading of unverified file types.

Join the discussion
CVE-2026-78083: CWE-352 Cross-Site Request Forgery (CSRF) in joomshaper.com SP Property extension for JoomlaCVE-2026-78083
0

A Cross-Site Request Forgery (CSRF) vulnerability exists in the SP Property extension for Joomla versions 1.0.0 through 4.1.3. The vulnerability affects the property booking and agent contact form submission endpoints, which process POST requests without verifying Joomla session anti-CSRF tokens. This flaw could allow attackers to perform unauthorized actions on behalf of authenticated users.

Join the discussion
CVE-2026-78082: CWE-89: Improper Neutralization of Special Elements used in an SQL Command in joomshaper.com SP Property extension for JoomlaCVE-2026-78082
0

An unauthenticated SQL injection vulnerability exists in the SP Property extension for Joomla versions 1.0.0 through 4.1.3. The vulnerability arises from unsafe concatenation of user-supplied parameters into SQL queries in the property search and map filtering features, allowing attackers to perform blind SQL injection attacks.

Join the discussion
CVE-2026-5399: CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in davidanderson Redux FrameworkCVE-2026-5399
0

The Redux Framework WordPress plugin is vulnerable to stored cross-site scripting (XSS) via the Slider field in User Profile settings in versions up to and including 4.5.13.1. The vulnerability arises from insufficient input sanitization and improper output escaping, allowing authenticated users with Subscriber-level access or higher to inject malicious scripts into their profiles. These scripts execute when an Administrator views the attacker's profile page.

Join the discussion
CVE-2026-15889: CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in arubadev Aruba HiSpeed CacheCVE-2026-15889
0

The Aruba HiSpeed Cache plugin for WordPress contains a stored cross-site scripting (XSS) vulnerability in all versions up to and including 3.0.14. This vulnerability arises from insufficient input sanitization and output escaping of post content, allowing authenticated users with Contributor-level access or higher to inject malicious scripts. These scripts execute when any user views the affected page, potentially compromising user interactions.

Join the discussion

Showing 1 to 10 of 702 results

Page 1 of 71
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses