Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

CVE-2026-86670: Password Hash With Insufficient Computational Effort in aircheng-org iWebShop-5CVE-2026-86670
0

CVE-2026-86670 is a medium severity vulnerability in aircheng-org iWebShop-5 up to version 5.15. It involves insufficient computational effort in password hashing within the Authentication Storage component, specifically in the controllers/admin.php file. The flaw can be exploited remotely but requires high complexity and is difficult to exploit. The vulnerability has been publicly disclosed, and an exploit exists, though no known active exploitation in the wild has been reported. The vendor has not yet responded or provided a fix.

Join the discussion
CVE-2026-86669: Improper Authentication in aircheng-org iWebShop-5CVE-2026-86669
0

A vulnerability was detected in aircheng-org iWebShop-5 up to 5.15. This affects the function Login of the file controllers/systemseller.php. Performing a manipulation of the argument Name results in improper authentication. It is possible to initiate the attack remotely. The exploit is now public and may be used. The project was informed of the problem early through an issue report but has not responded yet.

Join the discussion
CVE-2026-86668: Cross Site Scripting in aircheng-org iWebShop-5CVE-2026-86668
0

A cross-site scripting (XSS) vulnerability exists in aircheng-org iWebShop-5 versions 5.0 through 5.15 in the uploadFile function of controllers/pic.php. The vulnerability arises from unsafe manipulation of the outerSrc/selectPhoto argument, allowing remote attackers to inject malicious scripts. The vulnerability has been publicly disclosed, but no official vendor response or patch is currently available. The CVSS 4.0 base score is 5.3, indicating a medium severity level.

Join the discussion
CVE-2026-86666: Unrestricted Upload in aircheng-org iWebShop-5CVE-2026-86666
0

CVE-2026-86666 is a medium severity vulnerability in aircheng-org iWebShop-5 up to version 5.15. It involves an unrestricted file upload flaw in the upload_json/uploadFile function within controllers/pic.php. The vulnerability allows remote attackers to upload files without restriction. The exploit code has been publicly released. The vendor has been informed but has not yet responded or issued a fix.

Join the discussion
CVE-2026-86665: Missing Authorization in aircheng-org iWebShop-5CVE-2026-86665
0

A vulnerability was identified in aircheng-org iWebShop-5 up to 5.15. This issue affects the function Update::index of the file controllers/update.php. The manipulation leads to missing authorization. Remote exploitation of the attack is possible. The exploit is publicly available and might be used. The project was informed of the problem early through an issue report but has not responded yet.

Join the discussion

Showing 1 to 5 of 5 results

Filters:Package: pkg:github/aircheng-org/iWebShop-5
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses