Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
CVE-2026-16265: CWE-400 Uncontrolled Resource Consumption in WP MapsCVE-2026-16265 0 The WP Maps WordPress plugin before 4.9.7 does not perform a capability check in one of its AJAX actions and does not restrict the operation it dispatches, allowing users with a Subscriber account to trigger uncontrolled recursion that exhausts server resources, resulting in a Denial of Service. Join the discussion | CVE Database V5 | 08/07/2026, 06:00:14 UTC Added: 08/07/2026, 06:12:01 UTC |
CVE-2026-16263: CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in WP MapsCVE-2026-16263 0 The WP Maps WordPress plugin before 4.9.7 does not perform a capability check in one of its AJAX actions and does not properly validate a user-controlled path before using it in a file inclusion, allowing users with a Subscriber account to include and execute arbitrary existing local PHP files on the server. Join the discussion | CVE Database V5 | 08/07/2026, 06:00:14 UTC Added: 08/07/2026, 06:12:01 UTC |
CVE-2026-16262: CWE-352 Cross-Site Request Forgery (CSRF) in Estatik Real Estate PluginCVE-2026-16262 0 The Estatik Real Estate Plugin WordPress plugin before 4.3.3 does not bind its OAuth social login flow to the initiating user session, allowing an unauthenticated attacker to log a victim into an attacker-controlled account (login CSRF), so that the victim's subsequent activity is stored under and readable by the attacker. Join the discussion | CVE Database V5 | 08/07/2026, 06:00:14 UTC Added: 08/07/2026, 06:12:01 UTC |
CVE-2026-16258: CWE-502 Deserialization of Untrusted Data in Ajax Search LiteCVE-2026-16258 0 The Ajax Search Lite WordPress plugin before 4.14.5 does not prevent the deserialization of untrusted input, allowing unauthenticated attackers to perform PHP Object Injection. When a suitable POP chain is present via another installed Ajax Search Lite WordPress plugin before 4.14.5 or , this can be leveraged to achieve Remote Code Execution. Join the discussion | CVE Database V5 | 08/07/2026, 06:00:13 UTC Added: 08/07/2026, 06:12:01 UTC |
CVE-2026-16041: CWE-862 Missing Authorization in MStore APICVE-2026-16041 0 The MStore API WordPress plugin before 4.21.0 does not perform authorization or purchase-ownership checks on its REST product-review creation route, allowing an unauthenticated attacker to create WooCommerce product reviews with an attacker-chosen reviewer name, email and star rating on stores configured to accept reviews only from verified owners. Join the discussion | CVE Database V5 | 08/07/2026, 06:00:13 UTC Added: 08/07/2026, 06:12:01 UTC |
CVE-2026-16039: CWE-639 Authorization Bypass Through User-Controlled Key in MStore APICVE-2026-16039 0 The MStore API WordPress plugin before 4.21.0 does not restrict its vendor-orders endpoint to the caller's own orders, allowing any authenticated user, including Subscribers, to read every WooCommerce order in the store together with each customer's personal information. Join the discussion | CVE Database V5 | 08/07/2026, 06:00:13 UTC Added: 08/07/2026, 06:12:01 UTC |
CVE-2026-16038: CWE-862 Missing Authorization in MStore APICVE-2026-16038 0 The MStore API WordPress plugin before 4.21.0 does not verify the payment with the payment gateway before marking an order as paid on several of its payment-completion endpoints, allowing an unauthenticated attacker to mark an arbitrary order fully paid without paying and obtain goods or services for free. Join the discussion | CVE Database V5 | 08/07/2026, 06:00:13 UTC Added: 08/07/2026, 06:12:01 UTC |
CVE-2026-16030: CWE-287 Improper Authentication in MStore APICVE-2026-16030 0 The MStore API WordPress plugin before 4.21.0 does not correctly verify the cryptographic signature of the token used to authenticate its phone-based login, allowing unauthenticated attackers who know a registered user's phone number to forge a token and take over that user's account, including administrator accounts. Join the discussion | CVE Database V5 | 08/07/2026, 06:00:13 UTC Added: 08/07/2026, 06:12:01 UTC |
CVE-2026-15386: CWE-79 Cross-Site Scripting (XSS) in Meow GalleryCVE-2026-15386 0 The Meow Gallery WordPress plugin before 5.5.2 does not escape an attachment's alt text before outputting it into an attribute of the link it builds for linked galleries, allowing users with the Author role or above to store a JavaScript payload that executes in the browser of any visitor (including administrators) who views a post containing such a gallery. Join the discussion | CVE Database V5 | 08/07/2026, 06:00:12 UTC Added: 08/07/2026, 06:11:59 UTC |
CVE-2026-15361: CWE-89 SQL Injection in Content ViewsCVE-2026-15361 0 The Content Views WordPress plugin before 4.5 does not perform a capability check on one of its AJAX actions and does not properly sanitise attacker-supplied data before using it in a SQL query, allowing any authenticated user, including Subscribers, to perform SQL injection attacks. Join the discussion | CVE Database V5 | 08/07/2026, 06:00:12 UTC Added: 08/07/2026, 06:11:59 UTC |
Showing 1 to 10 of 23700 results