Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
0 A vulnerability in Brocade SANnav before 3.0.1 can have the Brocade Fabric OS switch admin password captured in plaintext within a memory swap file on the server hosting the Brocade SANnav Virtual Machine (VM). This can happen when the SANnav server encounters an Out Of Memory (OOM) condition. The vulnerability could allow an authenticated admin user with access to the server hosting the SANnav to potentially view the memory swap file and access the password(s). Join the discussion | CVE Database V5 | 10/08/2026, 06:07:03 UTC Added: 10/08/2026, 06:19:08 UTC |
A vulnerability in the Track Orders for WooCommerce WordPress plugin before version 1.2.7 allows unauthenticated attackers to access customers' billing details and order history by supplying the customer's email address. The plugin fails to verify order ownership before disclosing sensitive information such as name, email, phone number, postal address, and order history. Join the discussion | CVE Database V5 | 10/08/2026, 06:00:09 UTC Added: 10/08/2026, 06:19:10 UTC |
0 A vulnerability in the SMS Alert WordPress plugin before version 4.0.1 allows an administrator on a multisite network to access billing phone numbers of users from other sites. This occurs because the plugin does not verify if the acting administrator has permission to manage the selected users before disclosing their stored phone numbers. The issue affects multisite installations where the administrator's own site stores the SMS Alert gateway credentials. Join the discussion | CVE Database V5 | 10/08/2026, 06:00:09 UTC Added: 10/08/2026, 06:19:08 UTC |
0 The Wallet System for WooCommerce WordPress plugin before version 2.8.0 contains an authorization bypass vulnerability. It fails to verify that the wallet account specified in a withdrawal request belongs to the authenticated user submitting it. This flaw allows any authenticated user, including low-privilege roles like subscribers, to submit withdrawal requests against other users' wallets, specifying arbitrary amounts and payout destinations. Additionally, this can be used to indefinitely block the legitimate user from making withdrawals from their own wallet. Join the discussion | CVE Database V5 | 10/08/2026, 06:00:09 UTC Added: 10/08/2026, 06:19:08 UTC |
0 The Wallet System for WooCommerce WordPress plugin before 2.8.0 does not verify that the user submitting a wallet transfer owns the wallet being debited, allowing any authenticated user, including one with only the Subscriber role, to move an arbitrary user's wallet balance, including an administrator's, into an account they control. Join the discussion | CVE Database V5 | 10/08/2026, 06:00:08 UTC Added: 10/08/2026, 06:19:08 UTC |
The Wallet System for WooCommerce WordPress plugin before 2.8.0 does not perform any capability check, and relies on a token any authenticated user can obtain from a front-end page, before generating a report containing every customer's wallet transaction history, allowing any authenticated user, such as a subscriber, to disclose all users' names, email addresses, roles, transaction amounts, payment methods and dates. Join the discussion | CVE Database V5 | 10/08/2026, 06:00:08 UTC Added: 10/08/2026, 06:19:08 UTC |
0 The BackWPup WordPress plugin before 5.7.7 does not properly restrict the destination path of files extracted during a backup restore when its fallback archive library is used, allowing high-privileged users to write files outside the intended restore directory, potentially leading to remote code execution. Join the discussion | CVE Database V5 | 10/08/2026, 06:00:08 UTC Added: 10/08/2026, 06:19:08 UTC |
0 The BackWPup WordPress plugin before 5.7.7 does not verify that a request to its cron-triggered backup execution handler actually originates from WordPress's internal scheduled-event dispatch, allowing unauthenticated attackers to force any existing backup job to run immediately, independent of its configured trigger type or schedule. Join the discussion | CVE Database V5 | 10/08/2026, 06:00:08 UTC Added: 10/08/2026, 06:19:08 UTC |
CVE-2026-86826: CWE-200 Information Exposure in BackWPupCVE-2026-86826 0 The BackWPup WordPress plugin before 5.7.7 does not properly restrict web access to the working directory it uses during backup restores, allowing unauthenticated attackers, on webservers that do not honour .htaccess rules such as NGINX, to download the full backup archive (database dump and site files, including credentials and secret keys) left behind by an interrupted restore. Join the discussion | CVE Database V5 | 10/08/2026, 06:00:07 UTC Added: 10/08/2026, 06:19:08 UTC |
0 The Database Addon For WPForms ( wpforms entries ) WordPress plugin before 1.1.1 does not verify the CSRF nonce when the field is omitted and performs no capability check of its own, allowing attackers to delete arbitrary stored form entries by tricking a logged-in administrator into loading a crafted page. Join the discussion | CVE Database V5 | 10/08/2026, 06:00:07 UTC Added: 10/08/2026, 06:19:08 UTC |
Showing 1 to 10 of 145868 results