Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
CVE-2026-8615: CWE-862 Missing Authorization in ghera74 ilGhera Reviso Exporter for WooCommerceCVE-2026-8615 0 The ilGhera Reviso Exporter for WooCommerce plugin for WordPress has a vulnerability in versions up to and including 1.2.3 where a missing authorization check allows authenticated users with Subscriber-level access or higher to delete the stored Agreement Grant Token. This token is used to authenticate API calls between WooCommerce and the Reviso service. The vulnerability arises from the disconnect_callback() function, which lacks capability and nonce verification and is triggered via an AJAX action. Exploitation results in breaking the connection between WooCommerce and Reviso by removing the token. Join the discussion | CVE Database V5 | 09/09/2026, 05:31:05 UTC Added: 09/09/2026, 05:37:41 UTC |
CVE-2026-84908: CWE-862 Missing Authorization in getwpfunnels WPFunnels – Funnel Builder for WooCommerce with Checkout & One Click UpsellCVE-2026-84908 0 WPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsell plugin versions up to 3.12.13 suffer from a missing authorization vulnerability. The plugin registers an AJAX action accessible to unauthenticated users without nonce verification or capability checks. This flaw allows attackers to add arbitrary WooCommerce products to a cart at discounted prices configured on any funnel step, enabling price manipulation and potential revenue loss. Join the discussion | CVE Database V5 | 09/09/2026, 05:31:04 UTC Added: 09/09/2026, 05:37:41 UTC |
CVE-2026-83593: CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in quantumcloud WPBot – AI ChatBot for Live Support, Lead Generation, AI ServicesCVE-2026-83593 0 WPBot – AI ChatBot for Live Support, Lead Generation, AI Services WordPress plugin versions up to and including 8.7.3 contain a stored cross-site scripting (XSS) vulnerability via the 'conversation' parameter. This vulnerability arises from insufficient input sanitization and output escaping, allowing unauthenticated attackers to inject arbitrary scripts that execute when users access the affected pages. The nonce intended to protect this action is ineffective as it is localized into every public-facing page, failing to restrict unauthenticated access. Join the discussion | CVE Database V5 | 09/09/2026, 05:31:04 UTC Added: 09/09/2026, 05:37:41 UTC |
CVE-2026-76009: CWE-287 Improper Authentication in martinnguyen1990 Next-Cart Store to WooCommerce MigrationCVE-2026-76009 0 The Next-Cart Store to WooCommerce Migration WordPress plugin contains an authentication bypass vulnerability in all versions up to 3.9.8. This occurs because the plugin's REST API endpoint /wp-json/next_cart/v1/migration uses a permission callback that always returns true and relies on a hardcoded fallback token '__token__' if the token option is not set. This allows unauthenticated attackers to bypass authentication, execute arbitrary SQL commands including creating administrator accounts, and delete arbitrary files, potentially leading to full site takeover. Join the discussion | CVE Database V5 | 09/09/2026, 05:31:04 UTC Added: 09/09/2026, 05:37:41 UTC |
CVE-2026-75905: CWE-862 Missing Authorization in brechtvds WP Recipe MakerCVE-2026-75905 0 WP Recipe Maker plugin for WordPress up to version 10.8.0 contains an authorization bypass vulnerability. Authenticated users with contributor-level access or higher can take ownership of admin-authored recipes or unpublish them by exploiting improper authorization checks. Ownership transfer requires a specific plugin setting ('recipe_use_author' set to 'parent'), but unpublishing is possible regardless of this setting. The vulnerability has a medium severity rating with a CVSS score of 4.3. Join the discussion | CVE Database V5 | 09/09/2026, 05:31:05 UTC Added: 09/09/2026, 05:37:41 UTC |
CVE-2026-19946: CWE-862 Missing Authorization in awesomesupport Awesome Support – WordPress HelpDesk & Support PluginCVE-2026-19946 0 The Awesome Support WordPress plugin up to version 6.3.9 has a missing authorization vulnerability (CWE-862) in the wpas_do_mr_deny_user() function. This flaw allows authenticated users with subscriber-level access or higher to set a denial flag on any user account, including administrators, without proper capability checks. This results in permanently blocking the targeted user's moderated activation and sending a denial notification email to them. Join the discussion | CVE Database V5 | 09/09/2026, 05:31:03 UTC Added: 09/09/2026, 05:37:41 UTC |
CVE-2026-87737: CWE-208 Observable Timing Discrepancy in OCaml mirage-crypto-ecCVE-2026-87737 0 CVE-2026-87737 is a timing side-channel vulnerability in the mirage-crypto-ec package for OCaml, affecting versions before 2.4.0. The issue arises from the time required for a lookup during NIST elliptic-curve scalar multiplication depending on a secret value, potentially leaking sensitive information. The vulnerability has a medium severity with a CVSS score of 5.9. Join the discussion | CVE Database V5 | 09/09/2026, 04:21:37 UTC Added: 09/09/2026, 04:38:29 UTC |
CVE-2026-87736: CWE-125 Out-of-bounds Read in OCaml mirage-crypto-ecCVE-2026-87736 0 CVE-2026-87736 is a medium severity vulnerability in the mirage-crypto-ec package for OCaml, affecting versions before 2.3.0. It involves an out-of-bounds read when processing compressed elliptic curve public keys. This flaw does not impact confidentiality or integrity but can cause availability issues such as application crashes. Join the discussion | CVE Database V5 | 09/09/2026, 04:19:00 UTC Added: 09/09/2026, 04:38:29 UTC |
CVE-2026-87735: CWE-1284 Improper Validation of Specified Quantity in Input in OCaml mirage-crypto-pkCVE-2026-87735 0 CVE-2026-87735 is a medium severity vulnerability in the mirage-crypto-pk package for OCaml versions before 2.3.0. It involves an undocumented exception triggered by a small message during RSA encryption or decryption. This improper validation of the specified quantity in input may cause availability issues but does not impact confidentiality or integrity. Join the discussion | CVE Database V5 | 09/09/2026, 04:16:24 UTC Added: 09/09/2026, 04:38:29 UTC |
CVE-2026-87734: CWE-923 Improper Restriction of Communication Channel to Intended Endpoints in OCaml utcpCVE-2026-87734 0 CVE-2026-87734 is a high-severity vulnerability in the OCaml utcp package before version 0.0.6. It involves improper restriction of communication channels, specifically out-of-order segment reassembly, which can be exploited remotely to cause a denial of service (DoS). No patch or official remediation has been confirmed yet. There are no known exploits in the wild at this time. Join the discussion | CVE Database V5 | 09/09/2026, 04:13:55 UTC Added: 09/09/2026, 04:38:29 UTC |
Showing 1 to 10 of 19024 results