Skip to main content

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Package: pkg:npm/@aws/agentcore

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

0

A security vulnerability has been detected in GPAC up to f1219cde. Affected by this issue is the function mpgviddmx_process of the file filters/reframe_mpgvid.c of the component MPEG Video Reframer. Such manipulation leads to heap-based buffer overflow. The attack can be executed remotely. The exploit has been disclosed publicly and may be used. Upgrading to version abi-16.23 can resolve this issue. The name of the patch is afca1f1181668d85941d51ed1adf647807d5d975. Upgrading the affected component is recommended.

Join the discussion

A vulnerability was found in SourceCodester Online Faculty Clearance System 1.0. This affects the function move_uploaded_file of the file production/edit_picture.php of the component Profile Picture Upload. Performing a manipulation of the argument File results in unrestricted upload. The attack is possible to be carried out remotely. The exploit has been made public and could be used.

Join the discussion

The Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 4.1.23. This is due to the `PermissionManager::manage_permissions()` function being registered as a callback on WordPress core's `map_meta_cap` filter and unconditionally returning the always-true `'exist'` primitive for every capability check whenever the evaluated user ID is 1, without scoping this behavior to plugin-specific capabilities. This makes it possible for authenticated attackers whose account is user ID 1, even subscribers, to pass every WordPress capability check, including `manage_options`, `edit_plugins`, `edit_themes`, `promote_users`, and `update_core`, thereby elevating their privileges to administrator-equivalent power and achieving full site takeover, including remote code execution via the plugin and theme editors. Exploitation is only impactful when user ID 1 has been deliberately demoted to a lower-privilege role as a common administrator-account hardening practice; on default installations where user ID 1 retains the administrator role, no incremental privilege gain occurs.

Join the discussion

The Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'etn_shedule_objective' schedule_slot Parameter in all versions up to, and including, 4.1.23 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Join the discussion

The AI Engine – The Chatbot, AI Framework & MCP for WordPress plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.7.7 via the 'mediaId' parameter due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with subscriber-level access and above, to access and retrieve the transcribed contents of private audio attachments belonging to other users, including Administrators, via a supplied attachment ID. This vulnerability requires the Public API module to be enabled in the plugin settings; when disabled, the REST route is absent and the endpoint returns HTTP 404.

Join the discussion

CVE-2026-91004 is a SQL injection vulnerability in SourceCodester Online Faculty Clearance System version 1.0. The issue exists in the /delete_faculty1.php file where manipulation of the ID parameter allows remote attackers to perform SQL injection. The vulnerability has a medium severity with a CVSS score of 6.9. There is no information about an available patch or official fix. Exploit details have been publicly disclosed but there are no known exploits in the wild at this time.

Join the discussion

The WP Directory Kit WordPress plugin versions up to 1.5.7 contains an information exposure vulnerability. This flaw allows unauthenticated attackers to access draft and unapproved listings of other users via a public AJAX action, due to missing checks on listing status and ownership.

Join the discussion

The WP Directory Kit WordPress plugin versions up to 1.5.7 contains an information exposure vulnerability. This flaw allows users with Contributor-level roles to access non-public listing content, including password-protected and hidden fields of other users, due to missing authorization checks in one of its shortcodes.

Join the discussion

The WP Directory Kit WordPress plugin up to version 1.5.7 contains a SQL injection vulnerability. This occurs because some widget settings are not properly sanitized and escaped before being used in SQL queries. Authenticated users with Editor-level or higher privileges who have access to the page builder can exploit this flaw to perform SQL injection when the affected page is rendered.

Join the discussion

The Android application "ManabiPocket for Parents" by NTT DOCOMO BUSINESS, Inc. has an improper access control vulnerability in one of its components. This flaw allows a malicious application on the same device to exploit the affected component via an Intent and potentially access sensitive information. The vulnerability affects versions from 0 up to and including 1.2.3. The CVSS score is low, indicating limited impact and requiring user interaction for exploitation.

Join the discussion

Showing 1 to 10 of 131715 results

Filters:Package: pkg:npm/@aws/agentcore
Page 1 of 13172
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses