Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

CVE-2026-75860: CWE-269 Improper Privilege Management in JSON OptionsCVE-2026-75860
0

The JSON Options WordPress plugin up to version 0.0.4 contains a vulnerability where an action accessible to unauthenticated users lacks capability checks and nonce verification. This flaw allows attackers to update arbitrary WordPress options, potentially enabling user registration with the default role set to administrator. Exploiting this vulnerability can lead to privilege escalation and full site takeover.

Join the discussion
CVE-2026-74992: CWE-79 Cross-Site Scripting (XSS) in KirkiCVE-2026-74992
0

CVE-2026-74992 is a vulnerability in the Kirki WordPress plugin before version 6.2.3. It allows users with the Editor role to upload archives containing arbitrary files without proper validation or cleanup. This can lead to stored cross-site scripting (XSS) and potentially remote code execution (RCE) on some server configurations.

Join the discussion
CVE-2026-19699: CWE-863 Incorrect Authorization in GutenKitCVE-2026-19699
0

GutenKit WordPress plugin versions before 2.5.0 have insufficient authorization checks on certain REST API endpoints. This flaw allows users with Contributor role or higher to access mailing-list audience metadata from the connected marketing account. The vulnerability is classified as CWE-863 (Incorrect Authorization). There is no CVSS score or official patch information available yet.

Join the discussion
CVE-2026-19697: CWE-79 Cross-Site Scripting (XSS) in GutenKitCVE-2026-19697
0

GutenKit WordPress plugin versions before 2.5.0 have a stored Cross-Site Scripting (XSS) vulnerability due to improper sanitization of uploaded SVG files on some upload paths. This allows users with file upload capabilities, such as Authors, to upload malicious SVG files that can execute scripts when viewed by other users, including administrators.

Join the discussion
CVE-2026-19615: CWE-79 Cross-Site Scripting (XSS) in Admin and Site Enhancements (ASE)CVE-2026-19615
0

The Admin and Site Enhancements (ASE) WordPress plugin before version 9.0.1 contains a cross-site scripting (XSS) vulnerability due to improper sanitization of uploaded SVG files. This allows users with upload permissions to store SVG files containing JavaScript, which can execute in the browsers of users who open these files.

Join the discussion
CVE-2026-15049: CWE-434 Unrestricted Upload of File with Dangerous Type in Depicter — Popup & Slider BuilderCVE-2026-15049
0

The Depicter — Popup & Slider Builder WordPress plugin before version 4.8.0 contains a vulnerability where it does not validate file types during import uploads. This allows users with editor-level access to upload arbitrary files, including executable PHP scripts, to web-accessible directories. Such a flaw can lead to remote code execution if exploited.

Join the discussion
CVE-2026-13405: CWE-94 Improper Control of Generation of Code ('Code Injection') in Royal Addons for ElementorCVE-2026-13405
0

CVE-2026-13405 is a code injection vulnerability in the Royal Addons for Elementor WordPress plugin before version 1.7.1066. It occurs because the plugin does not properly sanitize custom widget markup before writing it to a file that is later executed. This flaw allows users with the manage_options capability, including certain subsite administrators on WordPress Multisite installations, to execute arbitrary PHP code.

Join the discussion
CVE-2026-75963: CWE-98 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') in liedekef Events Made EasyCVE-2026-75963
0

The Events Made Easy WordPress plugin up to version 3.2.5 contains a Local File Inclusion vulnerability via the eme_single_event_page_template function. Authenticated users with contributor-level access or higher can exploit this to include and execute arbitrary PHP files on the server. This can lead to bypassing access controls, data exposure, or remote code execution. The vulnerability triggers passively when a visitor loads the affected event page, requiring no further attacker interaction.

Join the discussion
CVE-2026-17153: CWE-862 Missing Authorization in siteground AI Agent by SiteGroundCVE-2026-17153
0

The AI Agent by SiteGround WordPress plugin up to version 1.2.7 contains an authorization bypass vulnerability. This flaw allows unauthenticated attackers to upload images to the WordPress media library by circumventing the usual upload_files capability restriction. The vulnerability arises because the plugin does not properly verify user authorization, relying solely on a nonce that is accessible to users with block editor access, including Contributors. This enables attackers with Contributor-level access or unauthenticated attackers to exploit the upload endpoint without proper permission checks.

Join the discussion
CVE-2026-73542: Improper Following of a Certificate's Chain of Trust in SEIKO EPSON CORPORATION Multiple SEIKO EPSON printers and scannersCVE-2026-73542
0

Multiple SEIKO EPSON printers and scanners contain revoked root certificates, which may allow a man-in-the-middle attacker to intercept communication data. The vulnerability involves improper following of a certificate's chain of trust. The CVSS score is 3.7, indicating a low severity risk. No specific affected versions or patch information are provided by the vendor at this time.

Join the discussion

Showing 1 to 10 of 19931 results

Filters:Package: pkg:bitnami/node
Page 1 of 1994
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses