Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
CVE-2026-78210 is a high-severity vulnerability in Octopus Deploy's Octopus Server where users with certain scoped permissions can execute arbitrary scripts in environments without proper authorization. This incorrect authorization issue affects multiple versions of Octopus Server released from 2019.5.9 up to but not including 2026.1.11739, 2026.2.0 up to but not including 2026.2.13364, and 2026.3.0 up to but not including 2026.3.13951. Join the discussion | CVE Database V5 | 10/01/2026, 04:36:23 UTC Added: 10/01/2026, 04:48:32 UTC |
0 CVE-2026-103538 is a medium severity vulnerability in ZongXR SuperMarket version 1.0.0.0. It affects the OrderController.deleteOrder function, where manipulation of the orderId parameter leads to missing authentication, allowing remote attackers to potentially delete orders without proper authorization. The vulnerability has a CVSS 4.0 base score of 6.9. Although the issue was reported early, the vendor has not yet responded or provided a patch. Exploit code has been publicly released, increasing the risk of attacks. Join the discussion | CVE Database V5 | 10/01/2026, 04:30:11 UTC Added: 10/01/2026, 04:48:32 UTC |
The Appointment Booking Plugin – LatePoint for WordPress versions up to and including 5.7.0 contains a critical vulnerability allowing unauthenticated attackers to execute arbitrary shortcodes. This occurs because the plugin improperly validates input before passing it to WordPress's do_shortcode function, enabling code injection during the booking flow. The vulnerability can lead to full compromise of confidentiality and integrity without requiring user interaction. Join the discussion | CVE Database V5 | 10/01/2026, 04:27:34 UTC Added: 10/01/2026, 04:48:32 UTC |
The Advanced Woo Labels – Product Labels & Badges for WooCommerce WordPress plugin is affected by a cross-site scripting (XSS) vulnerability due to improper input neutralization in the 'save_meta_boxes' function. This vulnerability allows authenticated users with Contributor-level access or higher to create labels that are rendered without proper escaping, potentially leading to unauthorized data modification. The issue affects all versions up to and including 2.51, with a partial patch applied in version 2.46. Join the discussion | CVE Database V5 | 10/01/2026, 04:27:33 UTC Added: 10/01/2026, 04:48:32 UTC |
0 The WP Popular Posts WordPress plugin up to version 7.4.2 has a vulnerability that allows unauthenticated attackers to access sensitive information from non-public post objects via the 'context' parameter in its REST API. This occurs because the plugin's REST route does not enforce permission checks and improperly passes the context parameter to WordPress core functions, exposing fields like raw title, content, password, meta, status, and guid that should not be publicly accessible. Join the discussion | CVE Database V5 | 10/01/2026, 04:27:33 UTC Added: 10/01/2026, 04:48:32 UTC |
0 CVE-2026-103536 is a medium severity vulnerability in ZongXR Supermarket version 1.0.0.0. It involves missing authentication in the OrderController.addOrder function, allowing remote attackers to manipulate the userId argument. The vulnerability could enable unauthorized order submissions. The issue was reported early to the project but remains unaddressed, and public exploit code is available. Join the discussion | CVE Database V5 | 10/01/2026, 04:15:10 UTC Added: 10/01/2026, 04:34:45 UTC |
CVE-2026-103641 is a medium severity vulnerability in the GEGL Radiance HDR loader used in Red Hat Enterprise Linux 10. The flaw causes an out-of-bounds read when an uncompressed scanline in an HDR image is shorter than the width declared in the file header. This can lead to application crashes when opening crafted HDR files. Join the discussion | CVE Database V5 | 10/01/2026, 03:43:06 UTC Added: 10/01/2026, 04:03:38 UTC |
0 CVE-2026-103533 is a path traversal vulnerability in the David-Crty databasement product affecting versions 1.7.0 and 1.7.1. The flaw exists in the database-servers API Endpoint, specifically in the RestoreRequest.php file, where manipulation of the schema_name argument can lead to path traversal. The vulnerability can be exploited remotely but requires high complexity and privileges. A fix is available in version 1.7.2. The CVSS score is low, indicating limited impact and exploitability. Join the discussion | CVE Database V5 | 10/01/2026, 02:45:11 UTC Added: 10/01/2026, 03:04:07 UTC |
0 BlueALSA (bluez-alsa/bluealsad) contains a division-by-zero vulnerability in its LC3plus sink decoder. This flaw can be triggered by a Bluetooth-adjacent attacker who sends a crafted RTP media header with a zero frame count, causing the daemon to crash. The issue affects builds compiled with LC3plus support enabled and results in a denial of service. The vulnerability has a low CVSS score of 2.1 and does not have known exploits in the wild. Join the discussion | CVE Database V5 | 10/01/2026, 02:28:18 UTC Added: 10/01/2026, 02:49:31 UTC |
0 The Newsletter – Send awesome emails from WordPress plugin (up to version 9.3.9) has a vulnerability where insufficiently protected credentials can be exposed via its public click-tracking REST route. This route allows unauthenticated attackers who obtain a signed click-tracking URL to receive a subscriber's permanent raw authentication cookie. The cookie can then be used to export subscriber data, modify profiles, or unsubscribe the subscriber without additional authentication. Signed URLs do not expire until the site's relink key rotates, enabling indefinite replay by anyone who observes such URLs. Join the discussion | CVE Database V5 | 10/01/2026, 02:27:46 UTC Added: 10/01/2026, 02:49:31 UTC |
Showing 1 to 10 of 142237 results