Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

CVE-2026-76074: CWE-862 Missing Authorization in rubengc AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPressCVE-2026-76074
0

The AutomatorWP plugin for WordPress contains an authorization bypass vulnerability in all versions up to and including 5.8.4. This flaw allows authenticated users with subscriber-level access or higher to retrieve the site's Campaign Monitor mailing list catalog, which should be restricted to users with manager capabilities. The vulnerability arises because the plugin does not properly verify user authorization and exposes a required nonce on all WordPress admin pages, enabling low-privilege users to exploit it without elevated access.

Join the discussion
CVE-2026-76057: CWE-862 Missing Authorization in rubengc AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPressCVE-2026-76057
0

The AutomatorWP plugin for WordPress contains an authorization bypass vulnerability in all versions up to and including 5.8.4. Authenticated users with subscriber-level access or higher can exploit this flaw to retrieve ConvertKit form data intended only for plugin managers. The vulnerability arises because the plugin does not properly verify user authorization before allowing access to this data. The required nonce for verification is exposed on all admin pages, making it accessible to any authenticated user who can access the WordPress admin area.

Join the discussion
CVE-2026-75027: CWE-862 Missing Authorization in themifyme Themify BuilderCVE-2026-75027
0

Themify Builder plugin for WordPress up to version 7.8.0 contains an authorization bypass vulnerability. This flaw allows unauthenticated attackers to modify styling data of arbitrary posts, including private and draft posts, by exploiting improper authorization checks. The vulnerability arises because a required nonce is exposed on all frontend pages, enabling attackers to obtain a valid nonce and bypass access controls.

Join the discussion
CVE-2026-19883: CWE-269 Improper Privilege Management in etruel WPeMatico RSS Feed FetcherCVE-2026-19883
0

The WPeMatico RSS Feed Fetcher plugin for WordPress contains a privilege escalation vulnerability due to a missing capability check in the wpematico_import_settings function. Authenticated users with subscriber-level access or higher can exploit this flaw to modify arbitrary site options, including changing the default user role to administrator and enabling user registration. This allows attackers to gain administrative access to the WordPress site. The vulnerability affects all versions up to and including 2.8.24. No official patch or remediation guidance has been provided yet.

Join the discussion
CVE-2026-77781: CWE-248 Uncaught ExceptionCVE-2026-77781
0

Tie::Hash::Regex versions before 2.0.0 for Perl will throw an exception on unparseable lookup keys. The FETCH, EXISTS and DELETE methods throw an exception when on malformed regular expressions. Each method falls back to a regex match when the key is not already stored in the hash, compiling the caller's key with a bare qr// and no eval guard. A key that is not a valid regular expression pattern, such as a single unmatched bracket, dies. An application that looks up externally supplied strings in a tied hash will die on an invalid key.

Join the discussion
ThreatFox IOCs for 2026-08-21
0

ThreatFox IOCs for 2026-08-21

Join the discussion
CVE-2026-73323CVE-2026-73323
0

CVE-2026-73323 is a reserved CVE identifier that has been rejected and does not correspond to a confirmed vulnerability. There is no technical description, CVSS score, or remediation information available.

Join the discussion
CVE-2026-53499: CWE-346: Origin Validation Error in NICMx FORT-validatorCVE-2026-53499
0

FORT Validator versions through 1.6.7 have an origin validation error in their RRDP processing that allows a delegated CA under the same Trust Anchor Locator to reference a victim CA’s RRDP URLs. This can cause the victim’s local snapshot to be deleted silently, removing validated route-origin data and potentially enabling route hijacking or loss of reachability. Version 1.6.8 includes a patch that rejects cross-origin RRDP snapshot and delta URLs. As a workaround, administrators can disable HTTP/RRDP while keeping rsync enabled, though this may cause data unavailability or staleness where rsync is unsupported.

Join the discussion
CVE-2026-34949: CWE-306: Missing Authentication for Critical Function in Combodo iTopCVE-2026-34949
0

CVE-2026-34949 is a vulnerability in Combodo iTop, a web-based IT service management tool. Prior to version 3.2.3, an unauthenticated user could delete the .readonly file, which is created during setup to prevent write actions. This deletion could allow unauthorized modification of the system. The issue has been fixed in version 3.2.3.

Join the discussion
CVE-2026-34948: CWE-200: Exposure of Sensitive Information to an Unauthorized Actor in Combodo iTopCVE-2026-34948
0

Combodo iTop versions prior to 3.2.3 have a vulnerability where only classes present in the SELECT clause are protected by the silos access check in OQL queries. This can lead to exposure of sensitive information to unauthorized actors. The issue is fixed in version 3.2.3.

Join the discussion

Showing 1 to 10 of 18005 results

Filters:Package: pkg:bitnami/wordpress
Page 1 of 1801
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses