Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
CVE-2026-13422: CWE-352 Cross-Site Request Forgery (CSRF) in harmonic_design HD QuizCVE-2026-13422 0 The HD Quiz WordPress plugin version 2.2.0 is vulnerable to a Cross-Site Request Forgery (CSRF) attack due to missing or incorrect nonce validation in the hdq_validate_nonce function. This vulnerability allows unauthenticated attackers to trick site administrators into performing unwanted actions such as deleting or modifying quizzes and questions, creating new quizzes, and changing plugin settings via forged requests. The vulnerability has a medium severity rating with a CVSS score of 4.3. Join the discussion | CVE Database V5 | 06/27/2026, 01:27:22 UTC Added: 06/27/2026, 02:06:28 UTC |
CVE-2026-13335: CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in codepeople CodePeople Post Map for Google MapsCVE-2026-13335 0 The CodePeople Post Map for Google Maps WordPress plugin is affected by a stored cross-site scripting (XSS) vulnerability in the 'cpm_point' post meta. This vulnerability exists in all versions up to and including 1.2.6. Authenticated users with Contributor-level access or higher can inject malicious scripts that execute when other users view the affected pages. The vulnerability arises from insufficient input sanitization and output escaping. Join the discussion | CVE Database V5 | 06/27/2026, 01:27:21 UTC Added: 06/27/2026, 02:06:28 UTC |
CVE-2026-13333: CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in trainingbusinesspros Groundhogg — CRM, Newsletters, and Marketing AutomationCVE-2026-13333 0 Groundhogg — CRM, Newsletters, and Marketing Automation WordPress plugin versions up to and including 4.5.5 are vulnerable to SQL Injection via the 'query[select]' parameter. Authenticated users with Sales Representative-level access or higher can exploit this vulnerability by injecting additional SQL queries due to insufficient input escaping and fallback to an unsanitized legacy query path when an invalid filter type is supplied. This vulnerability allows extraction of sensitive database information without impacting data integrity or availability. Join the discussion | CVE Database V5 | 06/27/2026, 01:27:21 UTC Added: 06/27/2026, 02:06:28 UTC |
CVE-2026-13331: CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in trainingbusinesspros Groundhogg — CRM, Newsletters, and Marketing AutomationCVE-2026-13331 0 Groundhogg — CRM, Newsletters, and Marketing Automation WordPress plugin versions up to and including 4.5.5 contain an SQL Injection vulnerability via the 'search' parameter. This vulnerability allows authenticated users with marketer-level access or higher to inject additional SQL commands due to insufficient input escaping and query preparation. The vulnerability can lead to unauthorized disclosure of sensitive database information. No official patch or remediation guidance is currently confirmed. Join the discussion | CVE Database V5 | 06/27/2026, 01:27:20 UTC Added: 06/27/2026, 02:06:28 UTC |
CVE-2026-11356: CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in vinod-dalvi Ivory Search – WordPress Search PluginCVE-2026-11356 0 The Ivory Search – WordPress Search Plugin is affected by a stored cross-site scripting (XSS) vulnerability in the 'menu_title' and 'menu_magnifier_color' settings. This vulnerability exists in all versions up to and including 5.5.15 due to insufficient input sanitization and output escaping. It allows authenticated users with administrator-level privileges or higher to inject malicious scripts that execute when other users access the affected pages. The vulnerability has a medium severity rating with a CVSS score of 4.4. Join the discussion | CVE Database V5 | 06/27/2026, 01:27:22 UTC Added: 06/27/2026, 02:06:28 UTC |
CVE-2025-59868: CWE-532 Insertion of sensitive information into log file in HCLSoftware Traveler for Microsoft OutlookCVE-2025-59868 0 HCL Traveler for Microsoft Outlook versions prior to 3.0.15 contains a vulnerability where sensitive information is inserted into log files. This exposure could allow an attacker with local access to gather sensitive application data, potentially facilitating further attacks. The vulnerability does not impact integrity or availability but results in high confidentiality impact. No official patch or remediation guidance is currently confirmed. Join the discussion | CVE Database V5 | 06/27/2026, 01:43:37 UTC Added: 06/27/2026, 02:06:27 UTC |
ThreatFox MISP Feed | 06/26/2026, 00:00:00 UTC Added: 06/27/2026, 00:06:10 UTC | |
CVE-2026-56414: CWE-434 in H.VIEW HV-500S6 IP CameraCVE-2026-56414 0 CVE-2026-56414 is a high-severity vulnerability in the H.VIEW HV-500S6 IP Camera. Authenticated users can upload arbitrary files via certificate-related upload interfaces without validation of file type, structure, or size. This allows placing unexpected or malformed data in filesystem locations intended for trusted certificate material, potentially impacting system integrity or behavior even after reboot. Join the discussion | CVE Database V5 | 06/26/2026, 23:00:39 UTC Added: 06/26/2026, 23:21:30 UTC |
CVE-2026-55975: CWE-78 in H.VIEW HV-500S6 IP CameraCVE-2026-55975 0 CVE-2026-55975 is a high-severity vulnerability in the H.VIEW HV-500S6 IP Camera. An authenticated user can supply unsanitized XML input to the device's certificate generation interface. This input is used in a backend command without proper validation, potentially allowing command execution with elevated privileges during certificate creation. Join the discussion | CVE Database V5 | 06/26/2026, 22:58:52 UTC Added: 06/26/2026, 23:21:30 UTC |
CVE-2026-33560: CWE-434 in Daktronics VFC-DMP-5000CVE-2026-33560 0 CVE-2026-33560 is a high-severity vulnerability in the Daktronics VFC-DMP-5000 file service. Authenticated users can upload arbitrary files without any validation or filtering, including executable binaries and scripts. This lack of file extension or content inspection allows potentially malicious files to be written directly to the server, posing a risk of code execution or system compromise. Join the discussion | CVE Database V5 | 06/26/2026, 22:48:56 UTC Added: 06/26/2026, 23:21:30 UTC |
Showing 1 to 10 of 9778 results