Skip to main content

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Package: pkg:npm/@opentelemetry/propagator-jaeger

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

During the Pwn2Own Ireland 2026 event, security researchers successfully exploited 45 unique zero-day vulnerabilities, including hacking the Samsung Galaxy S26 device three additional times. These exploits were rewarded with a total of $232,500 in cash prizes. No specific technical details or affected software versions are provided in the available information.

Join the discussion

CVE-2026-5769 is a medium severity vulnerability in Brocade SANnav before version 3.0.1 where the Brocade Fabric OS switch admin password may be stored in cleartext within a memory swap file on the SANnav VM server during an Out Of Memory (OOM) event. An authenticated admin user with access to the SANnav server could potentially read this swap file and obtain the password.

Join the discussion

A vulnerability in the Track Orders for WooCommerce WordPress plugin before version 1.2.7 allows unauthenticated attackers to access customers' billing details and order history by supplying the customer's email address. The plugin fails to verify order ownership before disclosing sensitive information such as name, email, phone number, postal address, and order history.

Join the discussion

A vulnerability in the SMS Alert WordPress plugin before version 4.0.1 allows an administrator on a multisite network to access billing phone numbers of users from other sites. This occurs because the plugin does not verify if the acting administrator has permission to manage the selected users before disclosing their stored phone numbers. The issue affects multisite installations where the administrator's own site stores the SMS Alert gateway credentials.

Join the discussion

The Wallet System for WooCommerce WordPress plugin before version 2.8.0 contains an authorization bypass vulnerability. It fails to verify that the wallet account specified in a withdrawal request belongs to the authenticated user submitting it. This flaw allows any authenticated user, including low-privilege roles like subscribers, to submit withdrawal requests against other users' wallets, specifying arbitrary amounts and payout destinations. Additionally, this can be used to indefinitely block the legitimate user from making withdrawals from their own wallet.

Join the discussion

The Wallet System for WooCommerce WordPress plugin before version 2.8.0 contains an authorization bypass vulnerability. This flaw allows any authenticated user, including those with minimal privileges such as the Subscriber role, to transfer funds from any user's wallet, including administrators, into an account they control. The vulnerability arises because the plugin does not verify ownership of the wallet being debited during a transfer request.

Join the discussion

The Wallet System for WooCommerce WordPress plugin before version 2.8.0 contains an information exposure vulnerability. It fails to perform proper capability checks and relies on a token accessible to any authenticated user. This flaw allows any authenticated user, including subscribers, to access a report with all customers' wallet transaction histories, exposing sensitive information such as names, email addresses, roles, transaction amounts, payment methods, and dates.

Join the discussion

A path traversal vulnerability (CWE-22) exists in the BackWPup WordPress plugin versions before 5.7.7. This flaw allows high-privileged users to write files outside the intended restore directory during backup restore operations when the fallback archive library is used. Exploitation could potentially lead to remote code execution.

Join the discussion

BackWPup WordPress plugin versions 3.3 up to but not including 5.7.7 contain a missing authorization vulnerability. This flaw allows unauthenticated attackers to trigger any existing backup job immediately, bypassing the intended scheduling and trigger restrictions. The vulnerability arises because the plugin does not verify that requests to its cron-triggered backup execution handler originate from WordPress's internal scheduled-event system.

Join the discussion

CVE-2026-86826 is an information exposure vulnerability in the BackWPup WordPress plugin versions before 5.7.7. The plugin does not properly restrict web access to its working directory used during backup restores. On webservers that do not honor .htaccess rules, such as NGINX, unauthenticated attackers can download the full backup archive, which may include sensitive data like database dumps, site files, credentials, and secret keys.

Join the discussion

Showing 1 to 10 of 145869 results

Filters:Package: pkg:npm/@opentelemetry/propagator-jaeger
Page 1 of 14587
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses