High Severity Threats
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Filtered Threats
Click on any threat for detailed analysis and mitigation recommendations
CVE-2026-78478: CWE-98 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') in Elated-Themes ManeCVE-2026-78478 0 The Mane WordPress theme by Elated-Themes contains a Local File Inclusion vulnerability in all versions up to and including 1.7. This vulnerability allows unauthenticated attackers to include and execute arbitrary files on the server, potentially leading to full code execution and access control bypass. Join the discussion | CVE Database V5 | 08/25/2026, 05:31:28 UTC Added: 08/25/2026, 05:52:48 UTC |
FURUNO ELECTRIC FA-50 CLASS B AIS TRANSPONDER uses hard-coded credentials and misses authentication for additional configuration 0 The FURUNO ELECTRIC FA-50 CLASS B AIS Transponder contains hard-coded credentials and lacks authentication for additional configuration. This vulnerability could allow unauthorized users to access and modify device settings without proper verification. No specific affected versions or patches are currently identified. There is no evidence of known exploits in the wild at this time. HighVulnerability Join the discussion | JVN Japan | 08/25/2026, 05:00:00 UTC Added: 08/25/2026, 05:12:52 UTC |
CVE-2026-19892: CWE-862 Missing Authorization in Infused Addons InfusedWoo ProCVE-2026-19892 0 CVE-2026-19892 is a high-severity privilege escalation vulnerability in the InfusedWoo Pro WordPress plugin. It affects all versions up to and including 5.1.17. The flaw arises from a missing proper authorization check in the ajax_iwar_preview_email() function, which relies solely on is_admin() for authorization. This allows authenticated users with subscriber-level access or higher to generate and retrieve password reset links for any WordPress user, including administrators, enabling account takeover. Join the discussion | CVE Database V5 | 08/25/2026, 03:27:05 UTC Added: 08/25/2026, 03:37:38 UTC |
CVE-2026-78685: CWE-940 Improper Verification of Source of a Communication Channel in Le-yan Medical Practice Management SystemCVE-2026-78685 0 Le-yan Medical Practice Management System version 2.4.2.8 contains a remote code execution vulnerability due to improper verification of the source of a communication channel. This flaw allows unauthenticated remote attackers to execute arbitrary operating system commands by delivering a crafted HTML page. The vulnerability is identified as CWE-940 and has a high severity with a CVSS score of 8.8. Join the discussion | CVE Database V5 | 08/25/2026, 02:05:09 UTC Added: 08/25/2026, 02:22:40 UTC |
CVE-2026-78679: External Control of File Name or Path in gitpython-developers GitPythonCVE-2026-78679 0 GitPython versions prior to 3.1.59 contain a vulnerability in the TagReference.create() function that allows arbitrary file reads. This occurs because a positional reference parameter bypasses the unsafe option guard, enabling attackers to supply a crafted reference value such as --file=<path> to read arbitrary files. The contents of these files are then returned in the annotated tag message. Join the discussion | CVE Database V5 | 08/25/2026, 01:30:36 UTC Added: 08/25/2026, 01:53:01 UTC |
CVE-2026-78678: Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') in gitpython-developers GitPythonCVE-2026-78678 0 GitPython versions before 3.1.59 have an incomplete denylist in the unsafe_git_revision_options guard, which omits the --contents and -S options. This allows attackers to read arbitrary files by passing these options to the Repo.blame() method. By supplying revision values such as --contents=/etc/passwd, attackers can leak file contents through the blame result returned to the caller. Join the discussion | CVE Database V5 | 08/25/2026, 01:30:35 UTC Added: 08/25/2026, 01:53:01 UTC |
CVE-2026-78677: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in gitpython-developers GitPythonCVE-2026-78677 0 GitPython versions prior to 3.1.59 contain a path traversal vulnerability that allows attackers to create arbitrary git directories outside the intended clone destination. This occurs because the --separate-git-dir option is omitted from unsafe_git_clone_options, enabling attackers to redirect repository metadata to attacker-controlled filesystem paths via the separate_git_dir parameter in Repo.clone_from() or Repo.clone(). This can lead to arbitrary directory creation and potential execution of hooks. Join the discussion | CVE Database V5 | 08/25/2026, 01:30:34 UTC Added: 08/25/2026, 01:53:01 UTC |
CVE-2026-78675: External Control of File Name or Path in gitpython-developers GitPythonCVE-2026-78675 0 GitPython versions before 3.1.59 contain a vulnerability where the merge_includes feature is not disabled when parsing .gitmodules files. This allows attackers to craft malicious .gitmodules files with include directives that reference arbitrary local file paths. When the repository's submodules are accessed, the GitConfigParser raises an exception that includes the first line of the targeted file, potentially disclosing sensitive local file content. Join the discussion | CVE Database V5 | 08/25/2026, 01:30:32 UTC Added: 08/25/2026, 01:52:59 UTC |
CVE-2026-76846: Insufficiently Protected Credentials in getgrav gravCVE-2026-76846 0 Grav versions prior to 2.0.16 have a vulnerability in the Twig sandbox configuration where the default denylist is incomplete. This allows attackers with page-edit permissions to access sensitive system configuration secrets via Twig template functions like config.get() or config.toArray() when config_access is enabled. Join the discussion | CVE Database V5 | 08/25/2026, 01:30:31 UTC Added: 08/25/2026, 01:52:59 UTC |
CVE-2026-76839: Insufficiently Protected Credentials in getgrav gravCVE-2026-76839 0 Grav CMS versions before 2.0.16 have a vulnerability where sandboxed Twig templates can access sensitive User object fields without proper filtering. This allows attackers with page-edit permissions to retrieve hashed passwords and two-factor authentication secrets. The vulnerability enables offline password cracking and potential authentication bypass. Join the discussion | CVE Database V5 | 08/25/2026, 01:30:31 UTC Added: 08/25/2026, 01:52:59 UTC |
Showing 1 to 10 of 5645 results