Console

Operations Dashboard

Real-time network intelligence and threat monitoring.

Exposed Surface — Shodan

LIVE • Shodan InternetDB
Global threat map visualization
Sample IP1.1.1.1
Open ports53, 80, 443, 2082, 2083, 2087
Aggregate (5 IPs)20 ports • 0 CVEs

External Dependency Health

LIVE • GitHub Status API
Overall
loading…

Live Malicious URL Stream

LIVE • abuse.ch URLhaus
0 recent
Loading stream…

Critical CVE Ticker

LIVE • NVD CVE 2.0
CVE-2026-12492
The Happy Coders OTP Login for WooCommerce WordPress plugin before 2.8 does not verify that a one-time password was actually validated before authenticating a user based on a supplied identifier, allowing unauthenticated attackers to log in as any existing user, including administrators, as well as to create new accounts.
9.8
CVE-2026-12525
The Redux Framework WordPress plugin before 4.5.13 does not restrict which user meta keys can be written when saving custom profile fields, allowing users with at least the Subscriber role to escalate their privileges to Administrator by submitting a crafted value while updating their own profile, on sites where the Redux Framework WordPress plugin before 4.5.13's user-profile (Users extension) feature is enabled.
8.8
CVE-2026-13741
The Digits: WordPress Mobile Number Signup and Login plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 9.1.0.5. This is due to missing authorization and role validation in the `dig_update_wpwc_custom_fields()` function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to escalate their privileges to Administrator by submitting a forged `digits_reg_userrole` value during profile update, granted the site administrator has configured the built-in DIGITS User Role field.
8.8
CVE-2026-15005
The Loco Translate plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.8.5. This is due to missing or incorrect nonce validation on the execTemplate function. This makes it possible for unauthenticated attackers to execute arbitrary PHP code on the server by supplying a php://filter stream wrapper URI as the 'template' parameter, which bypasses path validation and is passed directly to the include sink in execTemplate() via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
8.8
CVE-2026-12585
The Abandoned Cart Lite for WooCommerce WordPress plugin before 6.8.2 does not protect the integrity of its cart-recovery tokens or bind them to the requesting account, allowing unauthenticated attackers to forge a recovery link that logs them in as another user when the automatic-login option is enabled.
8.1

Public Event Throughput

LIVE • GitHub Events API
Loading…
Events
Window
Types
0

Malicious Infra by Country

LIVE • URLhaus + ip-api.com

Loading geo data…

Malware URL Activity

LIVE • abuse.ch URLhaus
Online
Offline
Added 24h
Top threat
Top reporter
Week total

EPSS Top Exploit Risk

LIVE • FIRST.org EPSS
Loading EPSS…

Active Exploit Queue

LIVE • CISA KEV catalog
6
P1 · 7d
18
P2 · 30d
0
P3 · older
Total tracked24
Ransomware-linked0
SourceCISA KEV

Latest Exploited Vulnerabilities — CISA KEV

Live • CISA + NVD
Threat Intel Hub

Live Surface & Malware Intelligence

Exposed Infrastructure — Shodan

5 hosts scanned
1.1.1.1
dollahan-rialto-ca.schoolloop.com
Ports (8)
53, 80, 443, 2082, 2083
CVEs
0
Tags
8.8.8.8
dns.google
Ports (2)
53, 443
CVEs
0
Tags
9.9.9.9
dns9.quad9.net
Ports (3)
53, 443, 853
CVEs
0
Tags
208.67.222.222
dns.opendns.com
Ports (4)
53, 80, 443, 5353
CVEs
0
Tags
140.82.114.4
lb-140-82-114-4-iad.github.com
Ports (3)
22, 80, 443
CVEs
0
Tags

Recent Malicious URLs — URLhaus

0 live

URLhaus 401