Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
CVE-2026-19905: SQL Injection in Jinher OACVE-2026-19905 0 A weakness has been identified in Jinher OA 1.0. Impacted is an unknown function of the file /C6/JHSoft.Web.HrmAttendance/attendance_out_approve.aspx. This manipulation of the argument httpOID causes sql injection. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way. Join the discussion | CVE Database V5 | 08/15/2026, 18:45:07 UTC Added: 08/15/2026, 18:56:39 UTC |
CVE-2026-18855: CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in jackdewey Link LibraryCVE-2026-18855 0 The Link Library plugin for WordPress contains a path traversal vulnerability that allows unauthenticated attackers to delete arbitrary files on the server. This occurs due to insufficient validation of file paths in the ll_delete_link_fields function in all versions up to and including 7.9.4. Exploitation requires the plugin option 'Delete local file on link deletion' to be enabled (disabled by default) and an attacker-submitted link to be permanently deleted by an administrator. Successful exploitation can lead to remote code execution if critical files such as wp-config.php are deleted. Join the discussion | CVE Database V5 | 08/15/2026, 18:25:57 UTC Added: 08/15/2026, 18:41:43 UTC |
CVE-2026-19904: Cross Site Scripting in SourceCodester Online Book Store SystemCVE-2026-19904 0 CVE-2026-19904 is a cross-site scripting (XSS) vulnerability found in SourceCodester Online Book Store System version 1.0. The vulnerability exists in the System Settings Module, specifically in the /admin/index.php?page=site_settings file. It allows remote attackers to inject malicious scripts. The exploit code has been publicly disclosed. The vulnerability has a medium severity rating with a CVSS score of 4.8. Join the discussion | CVE Database V5 | 08/15/2026, 18:00:08 UTC Added: 08/15/2026, 18:11:54 UTC |
CVE-2026-19903: Files or Directories Accessible in SourceCodester Online Clothing StoreCVE-2026-19903 0 CVE-2026-19903 is a medium severity vulnerability in SourceCodester Online Clothing Store version 1.0. It allows remote attackers to access files or directories via manipulation of the /db/shopping.sql file related to the SQL Database Backup component. The vulnerability has a CVSS 4.0 base score of 6.9 and has been publicly disclosed, but no official patch or remediation guidance is currently available. Join the discussion | CVE Database V5 | 08/15/2026, 17:45:07 UTC Added: 08/15/2026, 17:56:46 UTC |
CVE-2026-19598: CWE-863 Incorrect Authorization in sc0ttkclark Pods – Custom Content Types and FieldsCVE-2026-19598 0 The Pods – Custom Content Types and Fields WordPress plugin up to version 3.3.9 contains a critical privilege escalation vulnerability due to improper authorization checks in its AJAX router. This flaw allows unauthenticated attackers to bypass all access controls, potentially escalating privileges to Administrator or overwriting any user password, enabling full site takeover. Join the discussion | CVE Database V5 | 08/15/2026, 17:25:26 UTC Added: 08/15/2026, 17:41:57 UTC |
CVE-2026-19901: Hard-coded Credentials in LB-LINK X-PROCVE-2026-19901 0 CVE-2026-19901 is a critical security vulnerability in LB-LINK X-PRO version 1.0.22-20231206 involving hard-coded credentials in the /etc/config/easycwmp file. This flaw allows remote attackers to exploit the device, although the attack complexity is high and exploitability is difficult. The exploit code has been publicly released. The vendor has not provided any response or patch for this issue. Join the discussion | CVE Database V5 | 08/15/2026, 17:15:07 UTC Added: 08/15/2026, 17:26:40 UTC |
CVE-2026-19900: Hard-coded Credentials in LB-LINK X-PROCVE-2026-19900 0 CVE-2026-19900 is a critical vulnerability in LB-LINK X-PRO version 1.0.22-20231206 involving hard-coded credentials related to an unknown function of the /etc/shadow file. The vulnerability can be exploited remotely but requires a high degree of attack complexity. Exploit code is publicly available, though no vendor response or patch has been provided. Join the discussion | CVE Database V5 | 08/15/2026, 16:45:07 UTC Added: 08/15/2026, 16:56:46 UTC |
CVE-2026-19899: SQL Injection in SourceCodester Class and Exam Timetabling SystemCVE-2026-19899 0 CVE-2026-19899 is a medium severity SQL injection vulnerability in SourceCodester Class and Exam Timetabling System version 1.0. It affects an unknown function in the /edit_teacher.php file, where manipulation of the ID argument can lead to SQL injection. The vulnerability can be exploited remotely without authentication. Public exploit code has been disclosed, but no official patch or remediation guidance is currently available. Join the discussion | CVE Database V5 | 08/15/2026, 16:30:09 UTC Added: 08/15/2026, 16:41:44 UTC |
CVE-2026-19898: Improper Restriction of Excessive Authentication Attempts in VictoriaMetricsCVE-2026-19898 0 CVE-2026-19898 is a vulnerability in VictoriaMetrics version 1.146.0 affecting the VMAuth Authentication Endpoint. It allows improper restriction of excessive authentication attempts, potentially enabling an attacker to perform repeated authentication attempts remotely. The attack complexity is high and exploitability is difficult. A fix is available in version 1.147.0. Join the discussion | CVE Database V5 | 08/15/2026, 15:45:10 UTC Added: 08/15/2026, 15:56:46 UTC |
CVE-2026-20150: Improper Access Control in Cisco Cisco RoomOS SoftwareCVE-2026-20150 0 CVE-2026-20150 is a high severity vulnerability in Cisco RoomOS involving improper access control issues classified under CWE-284. Cisco conducted an internal security review that identified multiple vulnerabilities, which were addressed in a software hardening release. The vulnerability has a CVSS 3.1 score of 8.8, indicating high impact on confidentiality, integrity, and availability. No specific affected versions or patch links are provided in the available data. There are no known exploits in the wild at this time. Join the discussion | GCVE Database | 07/15/2026, 16:17:00 UTC Added: 08/15/2026, 15:53:49 UTC |
Showing 1 to 10 of 24294 results