Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
During the Pwn2Own Ireland 2026 event, security researchers successfully exploited 45 unique zero-day vulnerabilities, including hacking the Samsung Galaxy S26 device three additional times. These exploits were rewarded with a total of $232,500 in cash prizes. No specific technical details or affected software versions are provided in the available information. Join the discussion | Bleeping Computer | 10/08/2026, 06:32:16 UTC Added: 10/08/2026, 06:33:23 UTC |
0 CVE-2026-5769 is a medium severity vulnerability in Brocade SANnav before version 3.0.1 where the Brocade Fabric OS switch admin password may be stored in cleartext within a memory swap file on the SANnav VM server during an Out Of Memory (OOM) event. An authenticated admin user with access to the SANnav server could potentially read this swap file and obtain the password. Join the discussion | CVE Database V5 | 10/08/2026, 06:07:03 UTC Added: 10/08/2026, 06:19:08 UTC |
A vulnerability in the Track Orders for WooCommerce WordPress plugin before version 1.2.7 allows unauthenticated attackers to access customers' billing details and order history by supplying the customer's email address. The plugin fails to verify order ownership before disclosing sensitive information such as name, email, phone number, postal address, and order history. Join the discussion | CVE Database V5 | 10/08/2026, 06:00:09 UTC Added: 10/08/2026, 06:19:10 UTC |
0 A vulnerability in the SMS Alert WordPress plugin before version 4.0.1 allows an administrator on a multisite network to access billing phone numbers of users from other sites. This occurs because the plugin does not verify if the acting administrator has permission to manage the selected users before disclosing their stored phone numbers. The issue affects multisite installations where the administrator's own site stores the SMS Alert gateway credentials. Join the discussion | CVE Database V5 | 10/08/2026, 06:00:09 UTC Added: 10/08/2026, 06:19:08 UTC |
0 The Wallet System for WooCommerce WordPress plugin before version 2.8.0 contains an authorization bypass vulnerability. It fails to verify that the wallet account specified in a withdrawal request belongs to the authenticated user submitting it. This flaw allows any authenticated user, including low-privilege roles like subscribers, to submit withdrawal requests against other users' wallets, specifying arbitrary amounts and payout destinations. Additionally, this can be used to indefinitely block the legitimate user from making withdrawals from their own wallet. Join the discussion | CVE Database V5 | 10/08/2026, 06:00:09 UTC Added: 10/08/2026, 06:19:08 UTC |
0 The Wallet System for WooCommerce WordPress plugin before version 2.8.0 contains an authorization bypass vulnerability. This flaw allows any authenticated user, including those with minimal privileges such as the Subscriber role, to transfer funds from any user's wallet, including administrators, into an account they control. The vulnerability arises because the plugin does not verify ownership of the wallet being debited during a transfer request. Join the discussion | CVE Database V5 | 10/08/2026, 06:00:08 UTC Added: 10/08/2026, 06:19:08 UTC |
The Wallet System for WooCommerce WordPress plugin before version 2.8.0 contains an information exposure vulnerability. It fails to perform proper capability checks and relies on a token accessible to any authenticated user. This flaw allows any authenticated user, including subscribers, to access a report with all customers' wallet transaction histories, exposing sensitive information such as names, email addresses, roles, transaction amounts, payment methods, and dates. Join the discussion | CVE Database V5 | 10/08/2026, 06:00:08 UTC Added: 10/08/2026, 06:19:08 UTC |
0 A path traversal vulnerability (CWE-22) exists in the BackWPup WordPress plugin versions before 5.7.7. This flaw allows high-privileged users to write files outside the intended restore directory during backup restore operations when the fallback archive library is used. Exploitation could potentially lead to remote code execution. Join the discussion | CVE Database V5 | 10/08/2026, 06:00:08 UTC Added: 10/08/2026, 06:19:08 UTC |
0 BackWPup WordPress plugin versions 3.3 up to but not including 5.7.7 contain a missing authorization vulnerability. This flaw allows unauthenticated attackers to trigger any existing backup job immediately, bypassing the intended scheduling and trigger restrictions. The vulnerability arises because the plugin does not verify that requests to its cron-triggered backup execution handler originate from WordPress's internal scheduled-event system. Join the discussion | CVE Database V5 | 10/08/2026, 06:00:08 UTC Added: 10/08/2026, 06:19:08 UTC |
0 CVE-2026-86826 is an information exposure vulnerability in the BackWPup WordPress plugin versions before 5.7.7. The plugin does not properly restrict web access to its working directory used during backup restores. On webservers that do not honor .htaccess rules, such as NGINX, unauthenticated attackers can download the full backup archive, which may include sensitive data like database dumps, site files, credentials, and secret keys. Join the discussion | CVE Database V5 | 10/08/2026, 06:00:07 UTC Added: 10/08/2026, 06:19:08 UTC |
Showing 1 to 10 of 145869 results