Skip to main content

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Package: pkg:npm/@a2ui/web_core

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

0

A security flaw has been discovered in Totolink A3002MU Hh-B20211125.1046. Affected by this vulnerability is the function formWlWds of the file /boafrm/formWlWds. The manipulation of the argument submit-url results in buffer overflow. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks.

Join the discussion

In June 2026, the IETF published RFC 10008 defining a new HTTP method called QUERY, which behaves like a GET request with a body. This method is safe, idempotent, and cacheable, but many existing web infrastructure controls do not recognize it, potentially allowing bypasses of security mechanisms such as WAFs, CSRF protections, and caching rules. Various servers and frameworks handle QUERY inconsistently, with some rejecting it outright and others passing it through without inspection. The new method is not yet widely used but poses a risk due to gaps in existing security controls that assume a fixed set of HTTP verbs.

MediumNews
Join the discussion

The Save as PDF Plugin by PDFCrowd for WordPress up to version 4.6.1 contains a vulnerability that allows authenticated users with Contributor-level access or higher to invoke arbitrary PHP functions via the pdf_created_callback shortcode attribute. This occurs because user-supplied shortcode attributes are unsafely copied and later decrypted and executed without proper validation or capability checks. This flaw can lead to disclosure of sensitive plugin credentials and further server-side compromise.

Join the discussion

The WP2Social Auto Publish WordPress plugin contains a stored cross-site scripting (XSS) vulnerability affecting all versions up to and including 2.4.12. This vulnerability allows authenticated users with administrator-level permissions or higher to inject malicious scripts via the admin settings. The vulnerability specifically impacts multi-site WordPress installations or those where the unfiltered_html capability is disabled. Exploitation results in arbitrary script execution when a user accesses an injected page.

Join the discussion

The Pochipp WordPress plugin up to version 1.20.2 is vulnerable to reflected Cross-Site Scripting (XSS) via the 'keyword' parameter. The vulnerability arises from insufficient output escaping when rendering the search input value, allowing injection of arbitrary scripts. An unauthenticated attacker can exploit this by tricking a user with upload_files capability (Author or above) into clicking a crafted link, leading to script execution in the admin context.

Join the discussion

The Better Messages plugin for WordPress has an improper authentication vulnerability in all versions up to 2.15.33. The plugin's function that identifies internal AI bot accounts relies on a prefix check against an IP address sourced from a client-controlled header. This allows unauthenticated attackers to spoof AI bot identities, bypassing access controls to join restricted chat rooms, post messages, and read private message histories.

Join the discussion

Tutor LMS – eLearning and online course solution plugin for WordPress versions up to 4.0.8 is vulnerable to reflected Cross-Site Scripting (XSS) via the 'search' parameter. This vulnerability arises from insufficient input sanitization and output escaping, allowing unauthenticated attackers to inject arbitrary scripts that execute when a user interacts with crafted links. The CVSS score is 6.1, indicating a medium severity risk.

Join the discussion

The WP Recipe Maker WordPress plugin up to version 10.8.1 contains a code injection vulnerability allowing unauthenticated attackers to execute arbitrary registered shortcodes server-side. This occurs because user-supplied comment content is processed by a function that executes shortcodes before sanitization, enabling disclosure of sensitive data embedded in shortcode output. Exploitation requires the attacker's comment to be approved on the site, after which the malicious shortcode executes on every recipe page load.

Join the discussion

The Better Messages plugin for WordPress has an authorization bypass vulnerability in all versions up to and including 2.15.33. This flaw allows authenticated users with custom-level access or higher to access full message transcripts, thread metadata, and user data of any chat-room thread without proper authorization. The vulnerability is exploitable only when the chat room's 'only_joined_can_read' setting is set to its default value of '0'.

Join the discussion

Tutor LMS – eLearning and online course solution plugin for WordPress contains an authorization bypass vulnerability in all versions up to and including 4.0.8. This flaw allows authenticated users with subscriber-level access or higher to delete arbitrary WordPress posts permanently. The exploit requires a specific sequence involving profile-photo upload and topic creation before deleting targeted posts.

Join the discussion

Showing 1 to 10 of 136241 results

Filters:Package: pkg:npm/@a2ui/web_core
Page 1 of 13625
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses