Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

Hackers Exploiting Unpatched GeoServer Zero-Day
0

A zero-day SQL injection vulnerability in GeoServer's jsonArrayContains function allows attackers to achieve remote code execution. The flaw arises from improper sanitization of user-supplied arguments in database queries. Exploitation attempts began within hours of public disclosure, with hundreds of probes observed. No official patch is currently available, and threat actors continue to target this vulnerability. GeoServer is widely used across multiple industries, increasing the potential impact of this issue.

Join the discussion
AmnesiaStealer macOS Malware Steals Data, Controls Browser Sessions
0

AmnesiaStealer is a Rust-based macOS malware that steals sensitive user data including passwords, keychain items, browser data from Chromium-based browsers, and Safari cookies. It is distributed via a fake GitHub download page that tricks users into running a command in Terminal. The malware operates in three stages: initial infection, data harvesting, and a remote-control module that allows attackers to control browser sessions interactively. It uses known macOS bypasses to access protected data and installs persistence mechanisms. The malware overwrites browser encryption keys to decrypt future data and uses an old TCC bypass for Safari cookie theft. The remote-control component uses the Chrome DevTools Protocol to provide attackers with live control over victim browsers.

Join the discussion
CVE-2026-19811: Stack-based Buffer Overflow in TOTOLINK A800RCVE-2026-19811
0

CVE-2026-19811 is a high-severity stack-based buffer overflow vulnerability in TOTOLINK A800R version 4.1.2cu.5137_B20200730. The flaw exists in the setIpQosRules function within /cgi-bin/cstecgi.cgi of the firewall.so component. Remote attackers can exploit this vulnerability by manipulating the Comment argument, potentially leading to arbitrary code execution. Public exploit code is available, increasing the risk of attacks. No official patch or remediation guidance has been provided by the vendor as of now.

Join the discussion
CVE-2026-19617: Allocation of Resources Without Limits or Throttling in Red Hat Red Hat Enterprise Linux 10CVE-2026-19617
0

CVE-2026-19617 is a vulnerability in the libdm component of Red Hat Enterprise Linux 10. It allows a remote attacker to craft malicious LVM metadata with deeply nested structures, causing uncontrolled recursion in the libdm configuration parser. This leads to stack exhaustion and crashes of any LVM command reading the metadata, resulting in a denial of service (DoS). The vulnerability has a medium severity with a CVSS score of 5.7. No official patch or fix status is currently confirmed by Red Hat.

Join the discussion
CVE-2026-18039: CWE-269 Improper Privilege Management in Essential Addons for ElementorCVE-2026-18039
0

A vulnerability in the Essential Addons for Elementor WordPress plugin before version 6.7.2 allows unauthenticated attackers to register accounts with arbitrary roles, including administrator, by exploiting improper privilege management. This occurs when user-supplied registration fields overwrite reserved account attributes on sites with a custom profile field configured with a specific label.

Join the discussion
CVE-2026-16739: CWE-287 Improper Authentication in Epeken All Kurir for WoocommerceCVE-2026-16739
0

The Epeken All Kurir for Woocommerce WordPress plugin up to version 2.1.2 contains an improper authentication vulnerability. This flaw allows unauthenticated attackers to mark arbitrary orders as confirmed without verifying the request origin or actual payment status. In certain configurations, attackers can also mark orders as paid without authorization.

Join the discussion
CVE-2026-15205: CWE-89 SQL Injection in Paymob for WooCommerceCVE-2026-15205
0

CVE-2026-15205 is a SQL injection vulnerability in the Paymob for WooCommerce WordPress plugin before version 4.1.9. The plugin fails to properly sanitize a client-supplied identifier used in a SQL query within an unauthenticated payment callback. This query is executed before verifying the payment provider's HMAC signature, allowing unauthenticated attackers to perform SQL injection attacks. Exploitation can lead to reading arbitrary data from the database, including sensitive information such as user credentials, via both in-band and time-based blind SQL injection techniques.

Join the discussion
CVE-2026-14290: CWE-79 Cross-Site Scripting (XSS) in Embed Google Photos albumCVE-2026-14290
0

The Embed Google Photos album WordPress plugin through version 2.2.1 contains a Cross-Site Scripting (XSS) vulnerability. This flaw arises because the plugin does not properly escape a shortcode attribute value before outputting it inside an HTML attribute. Users with the Contributor role or higher can exploit this to inject arbitrary JavaScript. The injected script executes in the browsers of any users viewing the affected post, including administrators. No patch or official remediation guidance is currently available. There is no known exploitation in the wild at this time.

Join the discussion
CVE-2026-16810: CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in bitpressadmin Bit Form – Contact Form, Payment Forms, Multi Step Forms, Calculator & Custom Form BuilderCVE-2026-16810
0

The Bit Form plugin for WordPress is vulnerable to SQL Injection via the 'data[queryCondition]' parameter in all versions up to and including 3.2.0. This vulnerability allows authenticated administrators to inject additional SQL queries due to insufficient input escaping and query preparation.

Join the discussion
CVE-2026-12743: CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in cservit affiliate-toolkit – Multi-Network Affiliate & Amazon Product DisplayCVE-2026-12743
0

The affiliate-toolkit – Multi-Network Affiliate & Amazon Product Display WordPress plugin is vulnerable to a time-based SQL Injection via the 'orderby' parameter in all versions up to and including 3.8.8. This vulnerability allows authenticated users with administrator-level access or higher to inject additional SQL queries due to insufficient escaping and lack of proper query preparation. The vulnerability has a medium severity rating with a CVSS score of 4.9.

Join the discussion

Showing 1 to 10 of 23954 results

Filters:Package: pkg:generic/binutils
Page 1 of 2396
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses