Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
CVE Database V5 | 08/25/2026, 06:09:16 UTC | |
CVE-2026-78654: Improperly Controlled Modification of Object Prototype Attributes in cleverbrush frameworkCVE-2026-78654 0 A vulnerability has been found in cleverbrush framework and deep up to 4.4.0. This impacts the function deepExtend of the file libs/deep/src/deepExtend.ts. The manipulation leads to improperly controlled modification of object prototype attributes. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used. Upgrading to version 4.4.1 will fix this issue. The identifier of the patch is 810398c1308c500c3b8b6af380b5a89371389327. You should upgrade the affected component. Join the discussion | CVE Database V5 | 08/25/2026, 06:00:13 UTC Added: 08/25/2026, 06:09:16 UTC |
CVE-2026-78638: Path Traversal in peerigon unzip-crxCVE-2026-78638 0 CVE-2026-78638 is a path traversal vulnerability in the peerigon unzip-crx package versions 0.1 and 0.2.0. The flaw exists in the unzip function of the dist/index.js file within the Archive Extraction component. An attacker with local access can manipulate the destination argument to perform path traversal. Exploit code has been published, but the vendor has not yet responded or issued a fix. The vulnerability has a medium severity rating with a CVSS score of 4.8. Join the discussion | CVE Database V5 | 08/25/2026, 05:30:08 UTC Added: 08/25/2026, 05:52:49 UTC |
CVE-2026-78478: CWE-98 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') in Elated-Themes ManeCVE-2026-78478 0 The Mane WordPress theme by Elated-Themes contains a Local File Inclusion vulnerability in all versions up to and including 1.7. This vulnerability allows unauthenticated attackers to include and execute arbitrary files on the server, potentially leading to full code execution and access control bypass. Join the discussion | CVE Database V5 | 08/25/2026, 05:31:28 UTC Added: 08/25/2026, 05:52:48 UTC |
CVE-2026-78477: CWE-266 Incorrect Privilege Assignment in MVPThemes JawnCVE-2026-78477 0 The Jawn WordPress theme by MVPThemes contains a critical privilege escalation vulnerability (CWE-266) in all versions up to and including 1.4.2. This flaw allows unauthenticated attackers to elevate their privileges to administrator level. The vulnerability has a CVSS 3.1 score of 9.8, indicating a severe security risk. No official patch or remediation guidance has been provided yet. Join the discussion | CVE Database V5 | 08/25/2026, 05:31:29 UTC Added: 08/25/2026, 05:52:48 UTC |
CVE-2026-78470: CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in wedevs WP Project Manager ProCVE-2026-78470 0 WP Project Manager Pro plugin for WordPress versions up to and including 4.0.1 contains an SQL Injection vulnerability. This flaw allows authenticated users with Subscriber-level access or higher to inject additional SQL commands due to improper escaping and lack of query preparation. The vulnerability can lead to unauthorized extraction of sensitive database information. The CVSS score is 6.5, indicating a medium severity risk. No official patch or remediation guidance is currently provided by the vendor. No known exploits are reported in the wild. Join the discussion | CVE Database V5 | 08/25/2026, 05:31:28 UTC Added: 08/25/2026, 05:52:48 UTC |
CVE-2026-78467: CWE-862 Missing Authorization in Fluent Support Fluent Support ProCVE-2026-78467 0 Fluent Support Pro for WordPress up to version 2.3.1 has a missing authorization check vulnerability that allows authenticated users with Subscriber-level access or higher to perform unauthorized actions. This vulnerability is identified as CWE-862 and has a medium severity with a CVSS score of 4.3. No official patch or remediation guidance is currently provided by the vendor. Join the discussion | CVE Database V5 | 08/25/2026, 05:31:27 UTC Added: 08/25/2026, 05:52:48 UTC |
CVE-2026-78466: CWE-639 Authorization Bypass Through User-Controlled Key in Fluent Boars Fluent Boards ProCVE-2026-78466 0 Fluent Boards Pro plugin for WordPress contains an authorization bypass vulnerability due to missing validation on a user-controlled key. This flaw affects all versions up to and including 2.0.11 and allows authenticated users with Subscriber-level access or higher to perform unauthorized actions. The vulnerability is classified as an Insecure Direct Object Reference (CWE-639). Join the discussion | CVE Database V5 | 08/25/2026, 05:31:28 UTC Added: 08/25/2026, 05:52:48 UTC |
FURUNO ELECTRIC FA-50 CLASS B AIS TRANSPONDER uses hard-coded credentials and misses authentication for additional configuration 0 The FURUNO ELECTRIC FA-50 CLASS B AIS Transponder contains hard-coded credentials and lacks authentication for additional configuration. This vulnerability could allow unauthorized users to access and modify device settings without proper verification. No specific affected versions or patches are currently identified. There is no evidence of known exploits in the wild at this time. HighVulnerability Join the discussion | JVN Japan | 08/25/2026, 05:00:00 UTC Added: 08/25/2026, 05:12:52 UTC |
CVE-2026-78637: Argument Injection in Fdawgs node-popplerCVE-2026-78637 0 CVE-2026-78637 is a medium severity vulnerability in Fdawgs node-poppler versions 9.1.0 through 10.0.1. It involves argument injection via manipulation of the file_path argument in multiple PDF processing functions within src/index.js. The vulnerability can be exploited remotely. A patch identified by commit db6e3f79d3beb20601be7e59669c39811ae3c330 is recommended to fix the issue. No official remediation level or vendor advisory is provided in the data. Join the discussion | CVE Database V5 | 08/25/2026, 04:45:11 UTC Added: 08/25/2026, 05:07:39 UTC |
Showing 1 to 10 of 17940 results