Skip to main content

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Package: pkg:npm/@paperclipai/server

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

0

A flaw has been found in GPAC up to f1219cde. This vulnerability affects the function gf_mo_get_od_id of the file compositor/media_object.c of the component Compositor. Executing a manipulation can lead to use after free. The attack may be performed from remote. The exploit has been published and may be used. Upgrading to version abi-16.24 is able to resolve this issue. This patch is called e34f4ba349d55cd1849f0bcf4cf46552732e2db7. Upgrading the affected component is advised.

Join the discussion
0

CVE-2026-91086 is a heap-based buffer overflow vulnerability in the GPAC MPEG Video Reframer component, specifically in the mpgviddmx_process function. This vulnerability affects GPAC versions up to commit f1219cde. The flaw can be exploited remotely and has been publicly disclosed. A patch is available in version abi-16.23, which addresses this issue. Users are advised to upgrade to this version to mitigate the risk.

Join the discussion

CVE-2026-91005 is a medium severity vulnerability in SourceCodester Online Faculty Clearance System version 1.0. It involves an unrestricted file upload flaw in the move_uploaded_file function within production/edit_picture.php, allowing remote attackers to upload arbitrary files. An exploit for this vulnerability has been publicly disclosed.

Join the discussion

The Eventin WordPress plugin up to version 4.1.23 contains a privilege escalation vulnerability. The flaw arises because the plugin's permission management function grants all capabilities to the user with ID 1 unconditionally, regardless of their assigned role. This allows an attacker with user ID 1 but a lower-privilege role to gain administrator-level permissions, potentially leading to full site takeover and remote code execution via plugin or theme editors. The vulnerability is only exploitable if the user ID 1 account has been demoted from administrator, which is a common security hardening practice. Default installations where user ID 1 remains an administrator are not affected by privilege escalation.

Join the discussion

The Eventin WordPress plugin (up to version 4.1.23) contains a stored cross-site scripting (XSS) vulnerability via the 'etn_shedule_objective' schedule_slot parameter. Authenticated users with contributor-level access or higher can inject malicious scripts that execute when other users view the affected pages. This vulnerability arises from insufficient input sanitization and output escaping.

Join the discussion

The AI Engine – The Chatbot, AI Framework & MCP for WordPress plugin is affected by an authorization bypass vulnerability (CWE-639) in all versions up to and including 3.7.7. This flaw allows authenticated users with subscriber-level access or higher to access private audio attachment transcriptions belonging to other users, including administrators, by manipulating the 'mediaId' parameter. The vulnerability is exploitable only if the Public API module is enabled; otherwise, the REST endpoint is not available.

Join the discussion

CVE-2026-91004 is a SQL injection vulnerability in SourceCodester Online Faculty Clearance System version 1.0. The issue exists in the /delete_faculty1.php file where manipulation of the ID parameter allows remote attackers to perform SQL injection. The vulnerability has a medium severity with a CVSS score of 6.9. There is no information about an available patch or official fix. Exploit details have been publicly disclosed but there are no known exploits in the wild at this time.

Join the discussion

The WP Directory Kit WordPress plugin versions up to 1.5.7 contains an information exposure vulnerability. This flaw allows unauthenticated attackers to access draft and unapproved listings of other users via a public AJAX action, due to missing checks on listing status and ownership.

Join the discussion

The WP Directory Kit WordPress plugin versions up to 1.5.7 contains an information exposure vulnerability. This flaw allows users with Contributor-level roles to access non-public listing content, including password-protected and hidden fields of other users, due to missing authorization checks in one of its shortcodes.

Join the discussion

The WP Directory Kit WordPress plugin up to version 1.5.7 contains a SQL injection vulnerability. This occurs because some widget settings are not properly sanitized and escaped before being used in SQL queries. Authenticated users with Editor-level or higher privileges who have access to the page builder can exploit this flaw to perform SQL injection when the affected page is rendered.

Join the discussion

Showing 1 to 10 of 131716 results

Filters:Package: pkg:npm/@paperclipai/server
Page 1 of 13172
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses