Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

CVE-2026-82330: Out-of-bounds Read in Red Hat Red Hat Enterprise Linux 6CVE-2026-82330
0

A flaw was found in the file-pvr plugin in GIMP. When processing a specially crafted PVR image file, the VQ (compressed) decoder does not properly perform memory bounds checking. This missing validation results in a heap out-of-bounds read. This issue can result in an application crash, leading to a denial of service or a limited information disclosure of heap memory contents.

Join the discussion
CVE-2026-82328: Out-of-bounds Read in Red Hat Red Hat Enterprise Linux 6CVE-2026-82328
0

A flaw was found in the file-ico plugin in GIMP. When processing a specially crafted ICO image file, the plugin does not properly validate the used_clrs (palette count) parameter. This incorrect validation leads to improper memory bounds checking, resulting in a heap out-of-bounds read. This issue can result in an application crash, leading to a denial of service or a limited information disclosure of heap memory contents.

Join the discussion
CVE-2026-82327: Improper Validation of Array Index in Red Hat Red Hat Enterprise Linux 10CVE-2026-82327
0

A flaw was found in libsolv, a dependency-resolution library used by RPM-based package managers such as dnf and zypper to work with .solv repository cache files. When libsolv rewrites a .solv cache file, it reads directory-id values from the file's compressed filelist data without validating that they fall within the expected range. A corrupted or specially crafted .solv cache file (for example, one left in a torn state after an unclean system shutdown) can cause an out-of-bounds memory write when a tool such as dnf, yum, or zypper next processes it. Successful exploitation is expected to result in a crash of the affected tool (denial of service); it is not expected to allow arbitrary code execution because the out-of-bounds write always stores a fixed, non-attacker-controlled value.

Join the discussion
CVE-2026-82324: Out-of-bounds Read in Red Hat Red Hat Enterprise Linux 6CVE-2026-82324
0

A flaw was found in the file-iff (IFF/ILBM) plugin in GIMP. When processing a specially crafted IFF/ILBM image file, the plugin does not properly validate the HAM row size and improperly handles cases where the number of color planes (nPlanes) is zero. This causes a row size mismatch that bypasses memory bounds checking, resulting in heap out-of-bounds reads. This issue can result in an application crash, leading to a denial of service or a limited information disclosure of heap memory contents.

Join the discussion
CVE-2026-82227: CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in VillaTheme WPBulkyCVE-2026-82227
0

Contributor SQL Injection in WPBulky <= 1.2.2 versions.

Join the discussion
CVE-2026-82220: CWE-294 Authentication Bypass by Capture-replay in WPMU DEV ForminatorCVE-2026-82220
0

Unauthenticated Other Vulnerability Type in Forminator <= 1.57.1 versions.

Join the discussion
CVE-2026-82181: CWE-598 Use of GET request method with sensitive query strings in Le-yan Medical Practice Management SystemCVE-2026-82181
0

Medical Practice Management System developed by Le-yan has a Sensitive Data in URL vulnerability. Unauthenticated remote attackers can obtain sensitive information via victim's browser history or log files.

Join the discussion
CVE-2026-82112: Path Traversal in houtini-ai houtini-lmCVE-2026-82112
0

A flaw has been found in houtini-ai houtini-lm up to 2.13.2. The impacted element is an unknown function of the file src/index.ts of the component code_task_files. Executing a manipulation can lead to path traversal. The attack can be launched remotely. This patch is called 35d97bca0531894da36a85aedb95312da1bd5b7a. It is best practice to apply a patch to resolve this issue.

Join the discussion
CVE-2026-81767: CWE-862 Missing Authorization in yalla ya! Simple PaymentCVE-2026-81767
0

Unauthenticated Broken Access Control in Simple Payment <= 2.5.2 versions.

Join the discussion
CVE-2026-81761: CWE-862 Missing Authorization in Magepeople inc. WpEventlyCVE-2026-81761
0

Subscriber Broken Access Control in WpEvently <= 5.5.0 versions.

Join the discussion

Showing 1 to 10 of 18991 results

Filters:Package: pkg:bitnami/composer
Page 1 of 1900
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses