Skip to main content

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Package: pkg:bitnami/virtualenv

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

CVE-2026-78210 is a high-severity vulnerability in Octopus Deploy's Octopus Server where users with certain scoped permissions can execute arbitrary scripts in environments without proper authorization. This incorrect authorization issue affects multiple versions of Octopus Server released from 2019.5.9 up to but not including 2026.1.11739, 2026.2.0 up to but not including 2026.2.13364, and 2026.3.0 up to but not including 2026.3.13951.

Join the discussion

CVE-2026-103538 is a medium severity vulnerability in ZongXR SuperMarket version 1.0.0.0. It affects the OrderController.deleteOrder function, where manipulation of the orderId parameter leads to missing authentication, allowing remote attackers to potentially delete orders without proper authorization. The vulnerability has a CVSS 4.0 base score of 6.9. Although the issue was reported early, the vendor has not yet responded or provided a patch. Exploit code has been publicly released, increasing the risk of attacks.

Join the discussion

The Appointment Booking Plugin – LatePoint for WordPress versions up to and including 5.7.0 contains a critical vulnerability allowing unauthenticated attackers to execute arbitrary shortcodes. This occurs because the plugin improperly validates input before passing it to WordPress's do_shortcode function, enabling code injection during the booking flow. The vulnerability can lead to full compromise of confidentiality and integrity without requiring user interaction.

Join the discussion

The Advanced Woo Labels – Product Labels & Badges for WooCommerce WordPress plugin is affected by a cross-site scripting (XSS) vulnerability due to improper input neutralization in the 'save_meta_boxes' function. This vulnerability allows authenticated users with Contributor-level access or higher to create labels that are rendered without proper escaping, potentially leading to unauthorized data modification. The issue affects all versions up to and including 2.51, with a partial patch applied in version 2.46.

Join the discussion

The WP Popular Posts WordPress plugin up to version 7.4.2 has a vulnerability that allows unauthenticated attackers to access sensitive information from non-public post objects via the 'context' parameter in its REST API. This occurs because the plugin's REST route does not enforce permission checks and improperly passes the context parameter to WordPress core functions, exposing fields like raw title, content, password, meta, status, and guid that should not be publicly accessible.

Join the discussion

CVE-2026-103536 is a medium severity vulnerability in ZongXR Supermarket version 1.0.0.0. It involves missing authentication in the OrderController.addOrder function, allowing remote attackers to manipulate the userId argument. The vulnerability could enable unauthorized order submissions. The issue was reported early to the project but remains unaddressed, and public exploit code is available.

Join the discussion

CVE-2026-103641 is a medium severity vulnerability in the GEGL Radiance HDR loader used in Red Hat Enterprise Linux 10. The flaw causes an out-of-bounds read when an uncompressed scanline in an HDR image is shorter than the width declared in the file header. This can lead to application crashes when opening crafted HDR files.

Join the discussion

CVE-2026-103533 is a path traversal vulnerability in the David-Crty databasement product affecting versions 1.7.0 and 1.7.1. The flaw exists in the database-servers API Endpoint, specifically in the RestoreRequest.php file, where manipulation of the schema_name argument can lead to path traversal. The vulnerability can be exploited remotely but requires high complexity and privileges. A fix is available in version 1.7.2. The CVSS score is low, indicating limited impact and exploitability.

Join the discussion
0

BlueALSA (bluez-alsa/bluealsad) contains a division-by-zero vulnerability in its LC3plus sink decoder. This flaw can be triggered by a Bluetooth-adjacent attacker who sends a crafted RTP media header with a zero frame count, causing the daemon to crash. The issue affects builds compiled with LC3plus support enabled and results in a denial of service. The vulnerability has a low CVSS score of 2.1 and does not have known exploits in the wild.

Join the discussion

The Newsletter – Send awesome emails from WordPress plugin (up to version 9.3.9) has a vulnerability where insufficiently protected credentials can be exposed via its public click-tracking REST route. This route allows unauthenticated attackers who obtain a signed click-tracking URL to receive a subscriber's permanent raw authentication cookie. The cookie can then be used to export subscriber data, modify profiles, or unsubscribe the subscriber without additional authentication. Signed URLs do not expire until the site's relink key rotates, enabling indefinite replay by anyone who observes such URLs.

Join the discussion

Showing 1 to 10 of 142237 results

Filters:Package: pkg:bitnami/virtualenv
Page 1 of 14224
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses