Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

CVE-2026-16265: CWE-400 Uncontrolled Resource Consumption in WP MapsCVE-2026-16265
0

CVE-2026-16265 is a vulnerability in the WP Maps WordPress plugin before version 4.9.7. It arises because the plugin does not perform a capability check in one of its AJAX actions and does not restrict the operation it dispatches. This allows users with a Subscriber account to trigger uncontrolled recursion, which exhausts server resources and causes a Denial of Service (DoS).

Join the discussion
CVE-2026-16263: CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in WP MapsCVE-2026-16263
0

CVE-2026-16263 is a path traversal vulnerability in the WP Maps WordPress plugin before version 4.9.7. It arises because the plugin does not perform a capability check in one of its AJAX actions and fails to properly validate user-controlled paths before including files. This allows users with a Subscriber account to include and execute arbitrary existing local PHP files on the server.

Join the discussion
CVE-2026-16262: CWE-352 Cross-Site Request Forgery (CSRF) in Estatik Real Estate PluginCVE-2026-16262
0

The Estatik Real Estate Plugin for WordPress before version 4.3.3 contains a Cross-Site Request Forgery (CSRF) vulnerability in its OAuth social login flow. This flaw allows an unauthenticated attacker to log a victim into an attacker-controlled account without their consent. As a result, the victim's subsequent actions on the site are associated with the attacker's account, potentially exposing sensitive information to the attacker.

Join the discussion
CVE-2026-16258: CWE-502 Deserialization of Untrusted Data in Ajax Search LiteCVE-2026-16258
0

Ajax Search Lite WordPress plugin versions before 4.14.5 contain a vulnerability that allows deserialization of untrusted input. This flaw enables unauthenticated attackers to perform PHP Object Injection. If a suitable POP chain is available via another installed Ajax Search Lite plugin before 4.14.5, this vulnerability can lead to Remote Code Execution.

Join the discussion
CVE-2026-16041: CWE-862 Missing Authorization in MStore APICVE-2026-16041
0

CVE-2026-16041 is a missing authorization vulnerability in the MStore API WordPress plugin before version 4.21.0. It allows unauthenticated attackers to create WooCommerce product reviews without verifying purchase ownership, bypassing intended restrictions on review submissions. This can result in fake reviews with attacker-controlled reviewer names, emails, and star ratings on affected stores.

Join the discussion
CVE-2026-16039: CWE-639 Authorization Bypass Through User-Controlled Key in MStore APICVE-2026-16039
0

The MStore API WordPress plugin before version 4.21.0 contains an authorization bypass vulnerability in its vendor-orders endpoint. This flaw allows any authenticated user, including those with minimal privileges such as Subscribers, to access all WooCommerce orders in the store. Consequently, attackers can read sensitive customer personal information associated with these orders.

Join the discussion
CVE-2026-16038: CWE-862 Missing Authorization in MStore APICVE-2026-16038
0

The MStore API WordPress plugin before version 4.21.0 contains a missing authorization vulnerability. This flaw allows unauthenticated attackers to mark arbitrary orders as paid without verifying payment with the payment gateway. Exploiting this vulnerability could enable attackers to obtain goods or services without payment.

Join the discussion
CVE-2026-16030: CWE-287 Improper Authentication in MStore APICVE-2026-16030
0

CVE-2026-16030 is an authentication vulnerability in the MStore API WordPress plugin versions before 4.21.0. The plugin fails to properly verify the cryptographic signature of tokens used for phone-based login. This flaw allows unauthenticated attackers who know a registered user's phone number to forge authentication tokens and take over that user's account, including accounts with administrator privileges.

Join the discussion
CVE-2026-15386: CWE-79 Cross-Site Scripting (XSS) in Meow GalleryCVE-2026-15386
0

CVE-2026-15386 is a cross-site scripting (XSS) vulnerability in the Meow Gallery WordPress plugin versions before 5.5.2. It occurs because the plugin does not properly escape an attachment's alt text before inserting it into a link attribute for linked galleries. This allows users with Author role or higher to inject JavaScript payloads that execute in the browsers of visitors viewing posts containing the affected galleries.

Join the discussion
CVE-2026-15361: CWE-89 SQL Injection in Content ViewsCVE-2026-15361
0

The Content Views WordPress plugin before version 4.5 contains a SQL injection vulnerability due to missing capability checks on an AJAX action and improper sanitization of user-supplied data. This flaw allows any authenticated user, including those with minimal privileges such as Subscribers, to perform SQL injection attacks.

Join the discussion

Showing 1 to 10 of 23700 results

Filters:Package: pkg:npm/@msykes/events-manager
Page 1 of 2370
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses