Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
Feedback on my idea 0 This entry is a Reddit post linking to a Medium article where the author shares an idea about intelligent network scanners for routers. It is a discussion request rather than a report of a security vulnerability or threat. Join the discussion | Reddit Cybersecurity | 06/27/2026, 08:22:21 UTC Added: 06/27/2026, 08:51:16 UTC |
CVE-2026-9242: CWE-345 Insufficient Verification of Data Authenticity in metagauss RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User LoginCVE-2026-9242 0 The RegistrationMagic WordPress plugin up to version 6.0.8.6 contains an authentication bypass vulnerability due to insufficient verification of data authenticity in its PayPal IPN callback handler. This flaw allows unauthenticated attackers to forge IPN requests that manipulate payment log entries, enabling them to authenticate as any WordPress user, including administrators. Join the discussion | CVE Database V5 | 06/27/2026, 06:50:56 UTC Added: 06/27/2026, 07:21:29 UTC |
CVE-2026-9233: CWE-862 Missing Authorization in expresstech Quiz and Survey Master (QSM) – Easy Quiz and Survey MakerCVE-2026-9233 0 The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker WordPress plugin up to version 11.1.4 contains an authorization bypass vulnerability. Authenticated users with contributor-level access or higher can create, modify, and delete quiz output templates without proper authorization checks. This includes the ability to store unsanitized HTML content such as arbitrary script tags, potentially leading to content injection issues. Join the discussion | CVE Database V5 | 06/27/2026, 06:50:57 UTC Added: 06/27/2026, 07:21:29 UTC |
CVE-2026-3462: CWE-862 Missing Authorization in reepaydenmark Frisbii PayCVE-2026-3462 0 The Frisbii Pay plugin for WordPress contains a missing authorization vulnerability in its 'upload_csv' and 'process_batch' functions. This flaw affects all versions up to and including 1.8.9 and allows authenticated users with Subscriber-level access or higher to upload arbitrary CSV files. Exploiting this vulnerability enables overwriting of WooCommerce payment tokens, postmeta, and order meta data, potentially impacting data integrity. Join the discussion | CVE Database V5 | 06/27/2026, 06:50:59 UTC Added: 06/27/2026, 07:21:27 UTC |
CVE-2026-13295: CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in gpriday Page Builder by SiteOriginCVE-2026-13295 0 The Page Builder by SiteOrigin WordPress plugin contains a stored cross-site scripting (XSS) vulnerability in the panels_data parameter affecting all versions up to and including 2.34.3. Authenticated users with Contributor-level access or higher can inject malicious scripts into pages, which execute when other users view those pages. This occurs due to insufficient input sanitization and output escaping, combined with the storage of panels_data as post meta outside WordPress's usual filtering mechanisms. The vulnerability has a medium severity rating with a CVSS score of 6.4. Join the discussion | CVE Database V5 | 06/27/2026, 06:50:58 UTC Added: 06/27/2026, 07:21:27 UTC |
CVE-2026-12471: CWE-862 Missing Authorization in templatescoderthemes SpexoCVE-2026-12471 0 The Spexo WordPress theme by templatescoderthemes contains a vulnerability due to missing authorization checks in the activate_plugin function. This flaw affects all versions up to and including 2.0.11 and allows authenticated users with Subscriber-level access or higher to activate certain plugins without proper permissions. The vulnerability has a medium severity rating with a CVSS score of 4.3. Join the discussion | CVE Database V5 | 06/27/2026, 06:50:57 UTC Added: 06/27/2026, 07:21:27 UTC |
CVE-2026-12432: CWE-862 Missing Authorization in themeisle Stripe Payment Forms by WP Full Pay – Accept Credit Card Payments, Donations & SubscriptionsCVE-2026-12432 0 The WP Full Stripe Free plugin for WordPress (Stripe Payment Forms by WP Full Pay) contains a missing authorization vulnerability in versions up to and including 8.4.3. The vulnerability exists in the wpfs_update_failed_payment_status AJAX action, which lacks capability checks, nonce verification, and logged-in user verification. This allows unauthenticated attackers who have a valid Stripe Payment Intent ID to manipulate payment records, marking successful payments as failed and overwriting failure details. Join the discussion | CVE Database V5 | 06/27/2026, 06:50:59 UTC Added: 06/27/2026, 07:21:27 UTC |
CVE-2026-12399: CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in jegstudio Gutenverse – WordPress Blocks, Page Builder & Site EditorCVE-2026-12399 0 The Gutenverse – WordPress Blocks, Page Builder & Site Editor plugin for WordPress contains a stored cross-site scripting (XSS) vulnerability affecting all versions up to and including 3.8.0. This vulnerability arises from insufficient input sanitization and output escaping in admin settings. It allows authenticated users with editor-level permissions or higher to inject malicious scripts that execute when other users access the affected pages. The issue specifically impacts multi-site installations and sites where the unfiltered_html capability is disabled. Join the discussion | CVE Database V5 | 06/27/2026, 06:50:59 UTC Added: 06/27/2026, 07:21:27 UTC |
CVE-2026-11987: CWE-639 Authorization Bypass Through User-Controlled Key in dokaninc Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, EtsyCVE-2026-11987 0 Dokan: AI Powered WooCommerce Multivendor Marketplace Solution plugin for WordPress contains an authorization bypass vulnerability (CVE-2026-11987) affecting all versions up to 5.0.4. Authenticated users with subscriber-level access or higher can exploit a missing validation on the 'id' parameter to access other vendors' products, including unpublished drafts and pending listings. This exposure includes sensitive product details such as names, prices, SKUs, and descriptions. The issue arises because permission checks verify only generic vendor capabilities rather than confirming product ownership or author identity. Join the discussion | CVE Database V5 | 06/27/2026, 06:50:55 UTC Added: 06/27/2026, 07:21:27 UTC |
CVE-2026-11783: CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in dokaninc Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, EtsyCVE-2026-11783 0 A stored cross-site scripting (XSS) vulnerability exists in the Dokan AI Powered WooCommerce Multivendor Marketplace Solution plugin for WordPress. The issue arises from insufficient input sanitization and output escaping of the Product SKU field in all versions up to and including 5.0.4. Authenticated users with custom-level access or higher can inject malicious scripts that execute when any user, including unauthenticated visitors, views the affected pages. The vulnerability is triggered via the store search widget, which inserts unescaped AJAX response HTML into the DOM using jQuery's .html() method. Join the discussion | CVE Database V5 | 06/27/2026, 06:50:56 UTC Added: 06/27/2026, 07:21:27 UTC |
Showing 1 to 10 of 2441 results