Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
CVE-2026-81346: CWE-862 Missing Authorization in Frontend Admin by DynamiAppsCVE-2026-81346 0 The Frontend Admin by DynamiApps WordPress plugin before 3.29.11 does not perform a capability check on one of its AJAX actions, allowing any authenticated user, such as a subscriber, to delete arbitrary membership plans. Join the discussion | CVE Database V5 | 08/29/2026, 06:00:24 UTC Added: 08/29/2026, 06:22:50 UTC |
CVE-2026-81342: CWE-601 URL Redirection to Untrusted Site ('Open Redirect') in MasterStudy LMS WordPress PluginCVE-2026-81342 0 The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.43 does not validate a redirect parameter supplied during user registration before using it, allowing unauthenticated attackers to redirect users to arbitrary external URLs. Join the discussion | CVE Database V5 | 08/29/2026, 06:00:23 UTC Added: 08/29/2026, 06:22:50 UTC |
CVE-2026-81200: CWE-639 Authorization Bypass Through User-Controlled Key in MasterStudy LMS WordPress PluginCVE-2026-81200 0 The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.42 does not correctly restrict access to order information, allowing any user with the instructor role to read other users' order billing details, including name, email address, phone number and postal address, by enumerating order IDs. Join the discussion | CVE Database V5 | 08/29/2026, 06:00:23 UTC Added: 08/29/2026, 06:22:50 UTC |
CVE-2026-81026: CWE-284 Improper Access Control in MasterStudy LMS WordPress PluginCVE-2026-81026 0 The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.40 does not verify the amount, receiver, currency or status of a payment notification before marking the corresponding order completed, allowing unauthenticated users to complete full-price orders and gain access to paid content by paying only a token amount. Join the discussion | CVE Database V5 | 08/29/2026, 06:00:23 UTC Added: 08/29/2026, 06:22:50 UTC |
CVE-2026-80488: CWE-89 SQL Injection in WP Ultimate CSV ImporterCVE-2026-80488 0 The WP Ultimate CSV Importer WordPress plugin before 9.0 does not properly sanitise and escape imported field values before using them in a SQL statement, which could allow high privilege users such as admin to perform SQL injection attacks. Join the discussion | CVE Database V5 | 08/29/2026, 06:00:23 UTC Added: 08/29/2026, 06:22:50 UTC |
CVE-2026-80311: CWE-639 Authorization Bypass Through User-Controlled Key in Stripe Payment Forms by WP Full PayCVE-2026-80311 0 The Stripe Payment Forms by WP Full Pay WordPress plugin before 8.5.5 does not verify that a subscription belongs to the customer bound to the requesting customer-portal session before cancelling it, allowing a user with a confirmed portal session to cancel subscriptions belonging to other customers. Exploitation requires the attacker to know the target subscription's identifier, which is high-entropy and not enumerable through the Stripe Payment Forms by WP Full Pay WordPress plugin before 8.5.5. Join the discussion | CVE Database V5 | 08/29/2026, 06:00:23 UTC Added: 08/29/2026, 06:22:50 UTC |
CVE-2026-77786: CWE-863 Incorrect Authorization in Rank Math SEOCVE-2026-77786 0 The Rank Math SEO WordPress plugin before 1.0.277 does not check that the user requesting an automated SEO fix holds the capability WordPress itself requires for the settings being changed, allowing users with the Editor role to modify site-wide core WordPress settings that are reserved to administrators. Join the discussion | CVE Database V5 | 08/29/2026, 06:00:22 UTC Added: 08/29/2026, 06:22:46 UTC |
CVE-2026-77704: CWE-863 Incorrect Authorization in Booking for Appointments and Events CalendarCVE-2026-77704 0 The Booking for Appointments and Events Calendar WordPress plugin before 2.4.9 does not check that a user holds the required capability before letting them change an appointment's status, allowing customers to set arbitrary statuses on appointments they are booked on, including approving their own bookings that were left awaiting approval and overwriting another customer's booking status on a shared appointment. Join the discussion | CVE Database V5 | 08/29/2026, 06:00:22 UTC Added: 08/29/2026, 06:22:46 UTC |
CVE-2026-77012: CWE-918 Server-Side Request Forgery (SSRF)CVE-2026-77012 0 The 爱采集数据采集和发布插件 WordPress plugin through 1.0.0 does not require a per-install secret for one of its unauthenticated endpoints, relying on a hardcoded default, and does not validate the URLs or destination paths it is given, allowing unauthenticated attackers to read arbitrary files from the server, force it to issue arbitrary requests and retrieve the responses, and write attacker-supplied content outside the uploads directory. Join the discussion | CVE Database V5 | 08/29/2026, 06:00:22 UTC Added: 08/29/2026, 06:22:46 UTC |
CVE-2026-77010: CWE-284 Improper Access Control in HEL Online Classroom: AI-powered Online ClassroomsCVE-2026-77010 0 The HEL Online Classroom: AI-powered Online Classrooms WordPress plugin through 1.0.3 does not perform authorisation checks on its REST API routes and does not consistently enforce the per-class access code, allowing unauthenticated users to obtain a signed meeting join link for any classroom, including one protected by an access code, and to join it with moderator privileges. Join the discussion | CVE Database V5 | 08/29/2026, 06:00:22 UTC Added: 08/29/2026, 06:22:46 UTC |
Showing 1 to 10 of 18332 results