Live Threat Intelligence Radar
Real-time global cyber threat intelligence and monitoring
Geographic Threat Distribution
Heat map of affected countries
Live Threat Feed
Real-time updates
Threat Timeline
Trend analysis over time
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds
Build private feeds with layered filters and curated intel views.
Automations + integrations
Email alerts, webhooks, Slack, and routes into SIEMs or MISPs.
API access (baseline limits)
Unlock API v1 access; subscriptions increase rate limits.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Scan your servers for these threats
One command matches your running services against Radar by exact package (purl/CPE), with distro-backport-aware version checks. Bring your API key.
Threat Intelligence Database
Comprehensive database with detailed analysis
GNU Emacs versions prior to 31.2, including TRAMP through 2.8.2, contain a vulnerability that allows OS command injection via crafted filenames. This occurs because the tramp-user-regexp filter has an incomplete list of disallowed inputs, resulting in insufficient input validation. The issue is a regression from an incomplete fix for a previous vulnerability (CVE-2026-79992). Join the discussion | CVE Database V5 | 10/11/2026, 20:11:10 UTC Added: 10/11/2026, 20:19:06 UTC |
0 CVE-2026-108963 is a high-severity vulnerability in databasement before version 1.8.2 that allows authenticated users to achieve remote code execution. The issue arises because certain commands, such as mariadb-dump, are executed with a database name argument that can be controlled by the user. This argument injection enables indirect code execution, for example by writing to files like index.php. The vulnerability is due to improper neutralization of argument delimiters (CWE-88). Join the discussion | CVE Database V5 | 10/11/2026, 19:38:44 UTC Added: 10/11/2026, 19:49:04 UTC |
0 CVE-2026-108768 is a medium severity vulnerability in zhayujie CowAgent up to version 2.2.0. It involves improper resource allocation in the json.loads function of the Streaming Tool-Call Argument Handler component. The vulnerability can be exploited remotely without user interaction or privileges. Public exploit code exists, but there is no vendor response or patch available at this time. Join the discussion | CVE Database V5 | 10/11/2026, 18:59:38 UTC Added: 10/11/2026, 19:03:52 UTC |
CVE-2026-108925 is a medium severity cross-site scripting (XSS) vulnerability in the Cohesity NetBackup Administration Console web interface. It involves improper neutralization of script-related HTML tags, allowing an attacker to inject malicious scripts. This affects versions prior to 11.2 of the web interface. The vulnerability has a CVSS 3.1 score of 6.1, indicating a network attack vector with low complexity, no privileges required, but requiring user interaction. The impact includes limited confidentiality and integrity loss without availability impact. No known exploits are reported in the wild. No explicit patch or remediation information is provided in the available data. Join the discussion | CVE Database V5 | 10/11/2026, 18:11:27 UTC Added: 10/11/2026, 18:33:53 UTC |
0 CVE-2026-59508 is an SQL injection vulnerability in Interuse i-Bos version 3.0. It involves improper neutralization of special elements in SQL commands, which could allow an attacker to manipulate database queries. The vulnerability has a medium severity rating with a CVSS score of 5.9. No known exploits are reported in the wild, and no patch or remediation information is currently available. Join the discussion | CVE Database V5 | 10/11/2026, 17:51:21 UTC Added: 10/11/2026, 18:03:51 UTC |
0 CVE-2026-19740 is a denial-of-service vulnerability in the Zephyr Bluetooth LE Controller's Link Layer Control Procedure (LLCP) implementation. A peer device can exploit this flaw by sending a crafted sequence of LL Control PDUs that causes the controller to leak receive nodes from its limited pool, eventually exhausting resources and rendering Bluetooth inoperable until reboot. The issue affects Zephyr versions from 3.4.0 up to but not including 4.5.0. The vulnerability does not cause memory corruption or information disclosure, only availability impact. Join the discussion | CVE Database V5 | 10/11/2026, 17:15:08 UTC Added: 10/11/2026, 17:34:03 UTC |
0 CVE-2026-19739 is a denial of service vulnerability in the Zephyr Bluetooth Link Layer controller affecting versions from 3.4.0 up to but not including 4.5.0. The flaw involves improper handling of retained RX nodes during connection update procedures, which can lead to either a fatal controller error or exhaustion of the controller's RX buffer pool. This can be triggered remotely by an unauthenticated attacker within radio range without requiring pairing, bonding, or encryption. The impact is a persistent denial of service until the device is rebooted, with no memory corruption or data disclosure. Join the discussion | CVE Database V5 | 10/11/2026, 17:15:06 UTC Added: 10/11/2026, 17:34:03 UTC |
0 CVE-2026-19738 is a denial-of-service vulnerability in the Zephyr project's Bluetooth Link Layer Control Procedure (LLCP) implementation for Connected Isochronous Stream (CIS) creation. The flaw causes memory nodes to be retained and orphaned without release upon receiving invalid PDUs, leading to resource exhaustion. An attacker within radio range can exploit this without authentication or encryption by sending crafted LL Control PDUs. The impact is limited to availability, causing controller fatal errors or stalled flow control requiring system reboot to recover. Join the discussion | CVE Database V5 | 10/11/2026, 17:15:04 UTC Added: 10/11/2026, 17:34:03 UTC |
0 CVE-2026-19935 is a use-after-free vulnerability in the Zephyr Bluetooth LE host's handling of L2CAP connection-oriented channel (CoC) data when using dynamic PSMs. The issue arises because the system workqueue holds a pending work item referencing a channel object that may be freed or reused during channel teardown, leading to memory corruption or crashes. The vulnerability affects Zephyr versions from 2.0.0 up to and including 4.4.2. The flaw can be triggered remotely by an unauthenticated peer sending specific L2CAP frames. A fix has been implemented that routes the RX work to the Bluetooth workqueue and cancels the pending work item during teardown, preventing use-after-free conditions. Join the discussion | CVE Database V5 | 10/11/2026, 17:15:03 UTC Added: 10/11/2026, 17:34:05 UTC |
0 CVE-2026-19737 is a memory-safety vulnerability in the Zephyr project's i2s_esp32 driver affecting versions from 4.4.0 up to but not including 4.5.0. The flaw arises because the driver does not properly check stream pointers for certain I2S directions, leading to a NULL pointer dereference when a user-mode thread triggers an unwired direction. This results in a kernel-mode read from address zero, causing a system halt and denial of service. The vulnerability impacts availability but does not allow information disclosure or code execution. The issue is fixed by adding pointer checks and returning an error for unsupported directions. Join the discussion | CVE Database V5 | 10/11/2026, 17:15:01 UTC Added: 10/11/2026, 17:34:03 UTC |
Showing 1 to 10 of 17641 results