Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
A critical authentication bypass vulnerability (CVE-2026-76460) in Cisco Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC) allows remote unauthenticated attackers to bypass authentication via crafted API requests. This zero-day flaw has been actively exploited in the wild, enabling attackers to gain unauthorized access to the device's management interface and execute commands with root privileges. Cisco has released urgent patches for multiple versions and recommends upgrading immediately. No workarounds exist except restricting traffic via infrastructure ACLs. The US CISA has added this vulnerability to its Known Exploited Vulnerabilities catalog, urging rapid patching. Join the discussion | SecurityWeek | 09/17/2026, 06:19:52 UTC Added: 09/17/2026, 06:31:39 UTC |
0 Event Booking Manager for WooCommerce versions from 5.3.6 up to but not including 5.6.0 contain an improper access control vulnerability. This flaw allows users with Contributor-level access or higher to view sensitive payment gateway configuration details, including PayPal and Stripe secret keys. Join the discussion | CVE Database V5 | 09/17/2026, 06:00:14 UTC Added: 09/17/2026, 06:02:33 UTC |
The Motors WordPress plugin versions before 1.4.121 contain an authorization bypass vulnerability. This flaw allows unauthenticated attackers to access non-published car listings of any user by supplying the target's numeric user ID. The exposed data includes draft, pending, and private listings with details such as titles, prices, media URLs, and seller notes. Join the discussion | CVE Database V5 | 09/17/2026, 06:00:13 UTC Added: 09/17/2026, 06:02:33 UTC |
Master Addons for Elementor WordPress plugin versions 3.0.0 up to but not including 3.1.9 contains a missing authorization vulnerability. The plugin fails to properly verify user permissions on an AJAX action that deactivates Popup Builder popups, relying solely on a nonce that is publicly exposed to all visitors. This allows unauthenticated attackers to permanently disable any popup on the affected site. Join the discussion | CVE Database V5 | 09/17/2026, 06:00:13 UTC Added: 09/17/2026, 06:02:33 UTC |
0 CVE-2026-91014 is a reflected Cross-Site Scripting (XSS) vulnerability in the Realtyna Organic IDX plugin + WPL Real Estate WordPress plugin versions before 5.4.2. The vulnerability arises because some parameters are not properly sanitized and escaped before being reflected in the page. This allows unauthenticated attackers to execute arbitrary scripts in the browsers of visitors who follow a crafted link. Join the discussion | CVE Database V5 | 09/17/2026, 06:00:13 UTC Added: 09/17/2026, 06:02:33 UTC |
CVE-2026-91011 is a cross-site scripting (XSS) vulnerability in the EWWW Image Optimizer WordPress plugin versions before 8.7.7. The flaw allows authenticated users with author-level access or higher to inject arbitrary JavaScript into published content by exploiting improper escaping of image attribute values during page output rewriting. This malicious script executes in the browsers of users who view the affected pages. Join the discussion | CVE Database V5 | 09/17/2026, 06:00:13 UTC Added: 09/17/2026, 06:02:31 UTC |
0 The Invisible Anti-Spam & CAPTCHA — reCAPTCHA Alternative for All Forms WordPress plugin before version 5.1.1 contains a missing authorization vulnerability in its message deletion AJAX action. The plugin fails to properly check user capabilities and only verifies the presence of a nonce parameter without validating it. This flaw allows any authenticated user, including low-privileged roles such as subscribers, to permanently delete all stored form submissions. Join the discussion | CVE Database V5 | 09/17/2026, 06:00:13 UTC Added: 09/17/2026, 06:02:31 UTC |
0 Active Woot Products Tables for WooCommerce. 100% FREE WordPress plugin versions 2.1.2 up to but not including 2.1.3 lack authorization and CSRF checks in some AJAX actions. This allows any authenticated user, including those with low privileges such as subscribers, to change the title of arbitrary posts, pages, and products. Join the discussion | CVE Database V5 | 09/17/2026, 06:00:12 UTC Added: 09/17/2026, 06:02:31 UTC |
0 The Event Booking Manager for WooCommerce WordPress plugin versions 5.3.6 and 5.3.7 contain an authorization bypass vulnerability. This flaw allows unauthenticated attackers to access personal information of registered attendees by providing a booking reference number. The vulnerability only affects sites using the plugin's native checkout, not the default WooCommerce checkout. Join the discussion | CVE Database V5 | 09/17/2026, 06:00:12 UTC Added: 09/17/2026, 06:02:31 UTC |
0 The Autopay WordPress plugin versions before 5.0.1 contain an authorization flaw where a payment callback does not enforce signature verification. This allows unauthenticated users to access and delete stored payment parameters belonging to other customers' orders. Join the discussion | CVE Database V5 | 09/17/2026, 06:00:12 UTC Added: 09/17/2026, 06:02:31 UTC |
Showing 1 to 10 of 134957 results