Skip to main content

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Package: pkg:npm/@better-auth/oauth-provider

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

The Better Messages plugin for WordPress up to version 2.15.22 is vulnerable to reflected Cross-Site Scripting (XSS) via the 'icn' parameter. This vulnerability allows unauthenticated attackers to inject malicious scripts that execute when a user interacts with crafted content, such as clicking a link. The issue arises from insufficient input sanitization and output escaping.

Join the discussion

The Bookly plugin for WordPress, used for online scheduling and appointment booking, has an authorization bypass vulnerability (CWE-639) in all versions up to 28.1. This flaw allows unauthenticated attackers to access and enumerate AI booking conversation transcripts of any customer by manipulating the 'conversation_id' parameter. Sensitive customer data such as names, emails, phone numbers, and appointment details can be leaked. Attackers can also inject arbitrary messages into victim conversations, which are replayed to the AI system. The vulnerability arises because conversation IDs are sequential integers and conversations lack ownership or session identifiers.

Join the discussion

The Bold Page Builder WordPress plugin is affected by a stored cross-site scripting (XSS) vulnerability in versions up to and including 5.9.6. This vulnerability arises from a bypassable security filter and insufficient output sanitization, allowing authenticated users with Contributor-level access or higher to inject malicious scripts via the 'shortcode_content' parameter. These scripts execute when any user views the compromised page.

Join the discussion

The Advanced Popups WordPress plugin by codesupplyco contains a stored cross-site scripting (XSS) vulnerability in the 'Notification Button Link' field. This affects all versions up to and including 1.2.3. Authenticated users with author-level or higher privileges can inject malicious scripts that execute when other users view the affected pages.

Join the discussion

WP-Lister Lite for eBay WordPress plugin versions up to 3.8.9 are vulnerable to a stored cross-site scripting (XSS) flaw via an AJAX Cron Handler request parameter. This vulnerability allows unauthenticated attackers to inject malicious scripts that execute when a user accesses the affected page. The issue arises from insufficient input sanitization and output escaping.

Join the discussion

The Contest Gallery WordPress plugin (up to version 32.0.1) contains an Unauthenticated Arbitrary File Overwrite vulnerability due to insufficient validation of the 'baseUrlForFacebook' parameter. This flaw allows authenticated users with subscriber-level access or higher to overwrite files, potentially leading to remote code execution under certain conditions. The vulnerability is classified under CWE-434 and has a high severity rating with a CVSS score of 8.8.

Join the discussion

The JetFormBuilder — Dynamic Blocks Form Builder WordPress plugin is affected by a critical privilege escalation vulnerability in all versions up to and including 3.6.2. The flaw arises because the plugin does not verify that a submitted form ID corresponds to a JetFormBuilder form before processing the form schema and executing server-side validation callbacks. This allows unauthenticated attackers to escalate privileges by creating new administrator-level user accounts.

Join the discussion

The Ad Inserter – Ad Manager & AdSense Ads WordPress plugin up to version 2.8.16 contains an authorization bypass vulnerability. This flaw allows unauthenticated attackers to access administrator-configured header and footer code blocks that are intended to be hidden from public view. The issue arises from a missing capability check on the 'ai-debug-code' URL parameter.

Join the discussion

WP Directory Kit plugin for WordPress versions up to 1.5.4 is vulnerable to a blind SQL Injection via the 'order_by' parameter. Authenticated users with custom-level access or higher can exploit this vulnerability to append SQL queries and extract sensitive database information. The vulnerability arises from insufficient escaping and lack of proper query preparation.

Join the discussion

The TrueBooker – Appointment Booking and Scheduler System WordPress plugin up to version 1.2.3 contains an authorization bypass vulnerability. This flaw allows unauthenticated attackers to modify the email addresses of arbitrary user accounts, including administrators. Exploiting this can enable attackers to reset passwords and gain unauthorized access to affected accounts. The vulnerability is identified as CWE-862 (Missing Authorization) and has a critical CVSS score of 9.8.

Join the discussion

Showing 1 to 10 of 133784 results

Filters:Package: pkg:npm/@better-auth/oauth-provider
Page 1 of 13379
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses