Live Threat Intelligence Radar
Real-time global cyber threat intelligence and monitoring
Geographic Threat Distribution
Heat map of affected countries
Live Threat Feed
Real-time updates
Threat Timeline
Trend analysis over time
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds
Build private feeds with layered filters and curated intel views.
Automations + integrations
Email alerts, webhooks, Slack, and routes into SIEMs or MISPs.
API access (baseline limits)
Unlock API v1 access; subscriptions increase rate limits.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Scan your servers for these threats
One command matches your running services against Radar by exact package (purl/CPE), with distro-backport-aware version checks. Bring your API key.
Threat Intelligence Database
Comprehensive database with detailed analysis
0 `download_wheel()` runs `pip download` and hands the result straight to the seeder, with nothing checking the bytes it gets back. The embedded pip and setuptools wheels carry a `BUNDLE_SHA256` that virtualenv checks on every load, but a wheel fetched over the network for the periodic-update feature or the `--download` flag had no equivalent verification. A compromised index, a stale mirror, or a MITM'd download (when TLS is intercepted, e.g. via a misconfigured or malicious CA) could substitute a different wheel under the same distribution/version/filename, and virtualenv would cache and seed it into every environment created afterward with no warning. Fixed by computing the downloaded wheel's sha256 and comparing it against the digest PyPI's public JSON API reports for that exact release, independent of which index actually served the file. The check is skipped, not treated as failure, when a custom index (`PIP_INDEX_URL`, `PIP_EXTRA_INDEX_URL`, `PIP_INDEX`) is configured, since a private index can legitimately serve a different, intentionally rebuilt wheel. Fix: https://github.com/pypa/virtualenv/pull/3251 Join the discussion | CVE Database V5 | 10/04/2026, 19:25:06 UTC Added: 09/29/2026, 21:07:09 UTC |
0 ### Summary `pyvenv.cfg` is a line-based format with no escape syntax. `PyEnvCfg.write()` wrote values verbatim, while `PyEnvCfg._read_values()` parses the file with `str.splitlines()`. A value containing a line boundary therefore became additional configuration lines, and because reading is last-wins, the injected keys replaced any key written earlier in the file. ### Impact The `prompt` value is the reachable input: it is set by `--prompt`, by the `VIRTUALENV_PROMPT` environment variable, or from the config file, and `write()` emits `prompt` before `home`. A crafted prompt can therefore set `home` in the generated `pyvenv.cfg`: ```console $ virtualenv --prompt $'x"\nhome = /attacker/path\nprompt = "z' venv $ grep '^home' venv/pyvenv.cfg home = /attacker/path ``` `home` is what tooling reads to locate the base interpreter, so a consumer that trusts it can be pointed elsewhere. `implementation`, `version_info`, `version`, `executable`, `command` and `virtualenv` are also written before `prompt` and can be replaced the same way. This requires the prompt to come from somewhere other than the person running the command, for example a CI job templating a branch name into it, tooling deriving an environment name from user-supplied data, or an inherited `VIRTUALENV_PROMPT`. Where the operator supplies the prompt directly they already control the command line, and the effect is corruption rather than privilege gain: the value is truncated at the boundary and read back with a dangling quote. ### Details The boundary set is the one `str.splitlines()` recognizes, which is wider than `\n`: `\r`, `\v`, `\f`, the file, group and record separators, `U+0085`, `U+2028` and `U+2029` were all written through unchanged and all split the line when read back. ### Patches `PyEnvCfg.write()` now collapses those boundaries to spaces as it serializes each line, so it cannot emit a structurally invalid file regardless of what a caller places in `content`. ### Workarounds Do not pass externally influenced data as the virtualenv prompt. Strip line boundaries from any value before using it as `--prompt` or `VIRTUALENV_PROMPT`. Join the discussion | CVE Database V5 | 10/04/2026, 19:25:06 UTC Added: 09/29/2026, 21:07:09 UTC |
The anthropic-sdk package version 0.1.0 on PyPI contains malicious code that downloads and executes a remote script. It fingerprints the environment to detect sandboxing and delays execution before exfiltrating sensitive data such as credentials, environment variables, AI chat files, and SSH keys. If HTTPS exfiltration fails, it attempts DNS-based data exfiltration. The package also uses DNS to control execution centrally. Join the discussion | GCVE Database | 10/04/2026, 19:09:32 UTC Added: 10/04/2026, 21:09:39 UTC |
0 Mammoth.js versions from 1.3.0 up to but not including 1.12.3 contain a regular expression denial of service (ReDoS) vulnerability in the style map tokeniser. This vulnerability arises from overlapping regex alternatives in the lib/styles/parser/tokeniser.js component. An attacker can exploit this by supplying a crafted .docx file with an unterminated quoted string containing repeated backslash escapes, causing the Node.js event loop to block. Join the discussion | CVE Database V5 | 10/04/2026, 18:30:21 UTC Added: 10/04/2026, 17:19:07 UTC |
0 CVE-2026-105218 is a critical vulnerability in the go-pay gopay library versions prior to 1.5.119. The flaw disables TLS certificate verification in the default HTTP client, allowing man-in-the-middle attackers to impersonate payment provider APIs. This enables attackers to intercept and modify sensitive merchant credentials, signatures, transaction data, and payment-related responses. Join the discussion | CVE Database V5 | 10/04/2026, 18:30:21 UTC Added: 10/04/2026, 17:19:07 UTC |
CVE-2026-105217 is a vulnerability in Cockpit CMS versions 2.12.0 up to but not including 2.14.1 where TLS certificate verification is disabled in the cron.php web worker restart request. This allows network attackers performing man-in-the-middle attacks on the outbound connection to the site URL to present any certificate and capture the worker token, potentially enabling them to start the web worker. Join the discussion | CVE Database V5 | 10/04/2026, 18:30:21 UTC Added: 10/04/2026, 17:19:07 UTC |
go-micro versions before 6.0.0 have an improper certificate validation vulnerability. The shared TLS helper sets InsecureSkipVerify to true by default, allowing network attackers to impersonate services. This enables man-in-the-middle attackers to present any certificate and intercept or modify gRPC transport, HTTP and RabbitMQ broker, and Consul or etcd registry traffic, including authentication tokens and credentials. Join the discussion | CVE Database V5 | 10/04/2026, 18:30:21 UTC Added: 10/04/2026, 17:19:07 UTC |
0 A flaw has been found in invariant-systems-ai aiir up to 1.7.0. The affected element is an unknown function of the component Policy Gate Handler. Executing a manipulation can lead to improper verification of cryptographic signature. The attack can be executed remotely. It is advisable to upgrade the affected component. The GitHub repository of this project is not available anymore. This vulnerability only affects products that are no longer supported by the maintainer. Join the discussion | CVE Database V5 | 10/04/2026, 18:30:21 UTC Added: 10/04/2026, 17:19:07 UTC |
YesWiki versions before 4.6.7 have a cross-site scripting (XSS) vulnerability in the Bazar valeur action. This flaw allows page editors to inject malicious scripts by rendering unescaped HTML fetched from a remote URL. Exploitation involves attackers directing the vulnerable script to a controlled server returning crafted markup that executes JavaScript in viewers' browsers. The vulnerability has a medium severity rating with a CVSS score of 5.4. Join the discussion | GCVE Database | 10/04/2026, 18:30:20 UTC Added: 10/04/2026, 21:09:41 UTC |
CVE-2026-104402 is a medium severity vulnerability in farvisun Mindio Magic MCP (mindio-magic-mcp) versions up to 0.5.6. It involves the insertion of sensitive information into sent data, allowing retrieval of embedded sensitive data. The vulnerability has a CVSS 3.1 base score of 4.3, indicating a low impact on confidentiality with no impact on integrity or availability. No patch or remediation information is currently available. Join the discussion | GCVE Database | 10/04/2026, 18:30:20 UTC Added: 10/04/2026, 21:09:41 UTC |
Showing 1 to 10 of 18556 results