Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
CVE-2026-19332: Command Injection in NellyW8 MCP4EDACVE-2026-19332 0 CVE-2026-19332 is a medium severity command injection vulnerability in NellyW8 MCP4EDA version 1.0.0. It affects an unspecified functionality within the run_openlane/view_waveform component. The vulnerability arises from manipulation of the design_name or vcd_file arguments, allowing command injection. Exploitation requires local access with low privileges. No official patch or vendor response has been reported yet. Join the discussion | CVE Database V5 | 08/09/2026, 04:30:10 UTC Added: 08/09/2026, 04:41:46 UTC |
CVE-2026-19331: Path Traversal in bazylhorsey obsidian-mcp-serverCVE-2026-19331 0 CVE-2026-19331 is a path traversal vulnerability in bazylhorsey obsidian-mcp-server version 1.0.0. It affects the readCanvas and writeCanvas functions in the CanvasService.ts file. Exploitation requires local access to the system. The vendor has been informed but has not yet responded or issued a fix. The vulnerability has a medium severity rating with a CVSS score of 4.8. Join the discussion | CVE Database V5 | 08/09/2026, 04:15:10 UTC Added: 08/09/2026, 04:41:46 UTC |
DEFCON: New Red Team Tactic 0 EvilFontTool is a font-based deception technique that uses specially crafted fonts to display different text to human readers than what is actually stored in the document's machine-readable text. This allows attackers to manipulate documents such as HTML, DOCX, and PDFs to bypass security tools, evade AI content filters, and perform social engineering or red team operations. The technique can be used to poison help desk documentation, bypass email filters, and create traps within corporate networks. Demonstrations show how commands that appear benign to a user can actually execute malicious actions when copied and pasted. Join the discussion | Reddit NetSec | 08/09/2026, 03:59:22 UTC Added: 08/09/2026, 04:26:02 UTC |
CVE-2026-19330: Path Traversal in angrysky56 advanced-reasoning-mcpCVE-2026-19330 0 CVE-2026-19330 is a path traversal vulnerability in angrysky56 advanced-reasoning-mcp version 1.0.0. It affects specific functions in the src/index.ts file, allowing an attacker with local access to manipulate file paths. The vulnerability has a medium severity rating with a CVSS score of 4.8. No patch or official remediation has been provided by the vendor as of the publication date. Join the discussion | CVE Database V5 | 08/09/2026, 03:45:08 UTC Added: 08/09/2026, 04:12:00 UTC |
CVE-2026-10595: CWE-23 Relative Path Traversal in parisneo parisneo/lollmsCVE-2026-10595 0 CVE-2026-10595 is a path traversal vulnerability in parisneo/lollms version 2.1.0 affecting the SPA catch-all route in backend/routers/ui.py. It allows unauthenticated attackers to read arbitrary files on the server by exploiting improper sanitization of user-controlled path input. The issue is resolved in version 3. Join the discussion | CVE Database V5 | 08/09/2026, 03:52:26 UTC Added: 08/09/2026, 04:12:00 UTC |
CVE-2026-19329: Command Injection in andreahaku codex_mcpCVE-2026-19329 0 CVE-2026-19329 is a command injection vulnerability in the andreahaku codex_mcp tool affecting an unknown function in src/codex-process-simple.ts. The vulnerability arises from improper handling of the argument 'model' and requires local access to exploit. The project does not use versioning, so affected versions cannot be precisely identified. The issue was reported early to the project but has not yet received a response or fix. The CVSS 4.8 score indicates medium severity. Join the discussion | CVE Database V5 | 08/09/2026, 03:30:08 UTC Added: 08/09/2026, 03:41:45 UTC |
CVE-2026-19328: Path Traversal in aktsmm skill-ninja-mcp-serverCVE-2026-19328 0 CVE-2026-19328 is a path traversal vulnerability in aktsmm skill-ninja-mcp-server version 0.1.0. The flaw exists in several functions within src/installer.ts where the workspacePath argument can be manipulated to traverse directories. Exploitation requires local access. Upgrading to version 0.1.1 addresses this issue. Join the discussion | CVE Database V5 | 08/09/2026, 02:45:10 UTC Added: 08/09/2026, 03:11:57 UTC |
CVE-2026-19327: Path Traversal in abracadabra50 claude-seshCVE-2026-19327 0 CVE-2026-19327 is a path traversal vulnerability in abracadabra50 claude-sesh version 1.0.0. It affects the getEnrichedData/enrichSession function in src/services/enricher.ts. An attacker with local access can manipulate the sessionId argument to perform path traversal. A patch identified by commit 786c9d74800e6d0858b65778f31beb71b3983a50 is available to address this issue. Join the discussion | CVE Database V5 | 08/09/2026, 02:30:11 UTC Added: 08/09/2026, 03:11:57 UTC |
CVE-2026-19326: Path Traversal in Jevon-Zhong Ai-doctorCVE-2026-19326 0 CVE-2026-19326 is a path traversal vulnerability in Jevon-Zhong Ai-doctor version 0.0.1. It affects the deleteImage function in the filemanagement service, allowing local attackers with limited privileges to manipulate the imagePath argument to access unintended files. The vulnerability requires local access to exploit and has a medium severity score of 4.8. The vendor has not yet responded or provided a fix. Join the discussion | CVE Database V5 | 08/09/2026, 02:00:12 UTC Added: 08/09/2026, 02:26:46 UTC |
CVE-2026-19325: Path Traversal in IncomeStreamSurfer roo-code-memory-bank-mcp-serverCVE-2026-19325 0 CVE-2026-19325 is a medium severity path traversal vulnerability in the IncomeStreamSurfer roo-code-memory-bank-mcp-server component. It affects the functions readMemoryBankFile and appendMemoryBankEntry in the src/index.ts file, where manipulation of the file_name argument can lead to path traversal. Exploitation requires local access. The product uses a rolling release system, and no specific affected or fixed versions are disclosed. The vendor has not yet responded or provided a patch. Join the discussion | CVE Database V5 | 08/09/2026, 01:45:09 UTC Added: 08/09/2026, 02:26:46 UTC |
Showing 1 to 10 of 23403 results