Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
Large-scale DDoS attacks disrupted Threema secure messaging service 0 Multiple distributed denial-of-service (DDoS) attacks targeted the Threema secure messaging service earlier this week, causing severe disruptions to communications. [...] Join the discussion | Bleeping Computer | 08/16/2026, 17:29:52 UTC Added: 08/16/2026, 17:41:21 UTC |
Malicious code in upload-to-gcp (npm) 0 The npm package upload-to-gcp version 3.2.1 contains malicious code that executes a postinstall script during installation. This script collects host system identifiers and environment details, then sends this data to a suspicious external domain unrelated to Google Cloud Platform. This behavior occurs without user consent or disclosure, indicating a privacy and security risk. Join the discussion | GCVE Database | 08/15/2026, 18:07:45 UTC Added: 08/16/2026, 15:28:12 UTC |
Red Hat Security Advisory: python36:3.6 security updateCVE-2024-53899 0 A security update for the python36:3.6 module in Red Hat Enterprise Linux addresses a vulnerability in the virtualenv component that could allow command injection via virtual environment activation scripts. The issue is tracked as CVE-2024-53899 and is rated with an Important security impact by Red Hat. This vulnerability relates to improper handling of activation scripts in virtual environments, potentially enabling command injection attacks. Join the discussion | GCVE Database | 12/16/2024, 07:24:43 UTC Added: 08/16/2026, 15:28:11 UTC |
Malicious code in depcruise-wrap-stream-in-html (npm) 0 The npm package depcruise-wrap-stream-in-html version 99.9.1 is a hollow package designed to mimic an internal helper of dependency-cruiser. It installs a runtime dependency from an arbitrary HTTPS tarball hosted on an unrelated Google Cloud Storage bucket. This allows the bucket owner to change the tarball contents at any time without republishing to npm, bypassing registry scanning and version pinning. The package appears to be a dependency-confusion or smuggling lure. Join the discussion | GCVE Database | 08/15/2026, 18:11:29 UTC Added: 08/16/2026, 15:28:11 UTC |
A vulnerability has been found in SourceCodester Online Clothing Store 1.0. (CVE-2026-19903)CVE-2026-19903 0 A vulnerability in SourceCodester Online Clothing Store 1.0 affects the SQL Database Backup component, specifically in the /db/shopping.sql file. This flaw allows remote attackers to manipulate the system to gain access to files or directories. The vulnerability has a CVSS score of 5.3, indicating medium severity. Exploit details have been publicly disclosed, but no known exploits are currently active in the wild. No patch or remediation guidance is provided at this time. Join the discussion | GCVE Database | 08/15/2026, 18:31:18 UTC Added: 08/16/2026, 15:28:11 UTC |
A vulnerability was determined in SourceCodester Class and Exam Timetabling System 1.0. (CVE-2026-19899)CVE-2026-19899 0 SourceCodester Class and Exam Timetabling System 1.0 contains a SQL injection vulnerability in an unspecified function within the /edit_teacher.php file. This vulnerability allows remote attackers to manipulate the ID argument to execute unauthorized SQL commands. The vulnerability has a CVSS score of 7.3, indicating a medium severity level. No patch or remediation information is currently available. Exploit code has been publicly disclosed but there are no known exploits in the wild at this time. Join the discussion | GCVE Database | 08/15/2026, 18:31:18 UTC Added: 08/16/2026, 15:28:11 UTC |
A vulnerability was identified in LB-LINK X-PRO 1.0.22-20231206. (CVE-2026-19900)CVE-2026-19900 0 A high-severity vulnerability (CVE-2026-19900) exists in LB-LINK X-PRO version 1.0.22-20231206 involving hard-coded credentials related to an unknown function interacting with the /etc/shadow file. The vulnerability can be exploited remotely but requires a high degree of attack complexity. Exploit code is publicly available, though no known exploits in the wild have been reported. The vendor has not responded to disclosure and no patch or remediation information is available. Join the discussion | GCVE Database | 08/15/2026, 18:31:18 UTC Added: 08/16/2026, 15:28:11 UTC |
A vulnerability has been found in mangroup dtale up to 3.22.0. (CVE-2026-19897)CVE-2026-19897 0 A vulnerability in mangroup dtale up to version 3.22.0 affects the Login function in dtale/auth.py, allowing improper restriction of excessive authentication attempts. This issue can be exploited remotely but requires high complexity and no user interaction. The vulnerability has been publicly disclosed, but the project has not yet responded or provided a fix. The CVSS score is low (3.7), indicating limited impact primarily on confidentiality. Join the discussion | GCVE Database | 08/15/2026, 18:31:18 UTC Added: 08/16/2026, 15:28:10 UTC |
A vulnerability was found in VictoriaMetrics up to 1.146.0. (CVE-2026-19898)CVE-2026-19898 0 VictoriaMetrics up to version 1.146.0 contains a vulnerability in the VMAuth Authentication Endpoint's requestHandler function that allows improper restriction of excessive authentication attempts. This issue can be exploited remotely but requires high attack complexity and no privileges or user interaction. The vulnerability has a low severity score and a patch is available in version 1.147.0. Join the discussion | GCVE Database | 08/15/2026, 18:31:18 UTC Added: 08/16/2026, 15:28:10 UTC |
A vulnerability was found in SourceCodester Online Book Store System 1.0. (CVE-2026-19904)CVE-2026-19904 0 A cross-site scripting (XSS) vulnerability exists in SourceCodester Online Book Store System 1.0 within the System Settings Module at /admin/index.php?page=site_settings. The vulnerability allows remote attackers with high privileges to perform reflected XSS attacks. The vulnerability has a low severity score and no known exploits in the wild have been reported. No patch or remediation information is currently available. Join the discussion | GCVE Database | 08/15/2026, 18:31:18 UTC Added: 08/16/2026, 15:28:10 UTC |
Showing 1 to 10 of 4811 results