Skip to main content

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Package: pkg:bitnami/consul

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

0

CVE-2026-19575 is a memory safety vulnerability in the Zephyr RTOS affecting the device_deinit() system call handler when both CONFIG_USERSPACE and CONFIG_DEVICE_DEINIT_SUPPORT are enabled. The vulnerability allows a local unprivileged user thread to pass a kernel object pointer that bypasses proper type validation, leading to an indirect call to an arbitrary address in supervisor mode, enabling full kernel code execution. This flaw affects Zephyr versions from 4.2.0 through 4.4.2 inclusive. The issue is fixed by restricting the object type check to driver objects only, preventing misuse of arbitrary kernel objects.

Join the discussion

CVE-2026-19569 is an integer overflow vulnerability in the Zephyr kernel's dynamic object allocation code. It occurs when user-mode threads provide a size value close to the maximum unsigned integer, causing arithmetic wrap-around and resulting in undersized heap allocations. This allows an unprivileged user-mode thread to perform out-of-bounds writes in supervisor mode, potentially corrupting kernel memory and escaping the userspace sandbox. Exploitation requires specific kernel configurations (CONFIG_USERSPACE and CONFIG_DYNAMIC_OBJECTS) and a thread with an assigned resource pool. The vulnerability affects Zephyr versions from 3.5.0 through 4.4.2. A fix has been implemented to reject overflowing size computations and free partially built descriptors.

Join the discussion
0

CVE-2026-19574 is a high-severity vulnerability in the Zephyr project affecting ARM64 memory domain management. The ARM64 MMU back-end uses a simple round-robin counter to allocate ASIDs (address space identifiers) for memory domains, but with only 255 ASIDs available, the counter can wrap and assign the same ASID to multiple live domains. This causes TLB entries from one domain to remain accessible when another domain with the same ASID is active, breaking memory domain isolation. Exploitation requires a CONFIG_USERSPACE application on ARM64 creating more than 255 memory domains, but domain creation APIs are supervisor-only, limiting direct user control. The vulnerability allows a user-mode thread in one domain to read and write memory of another domain, violating memory isolation boundaries. A fix is implemented that scans live domains to avoid ASID reuse and fails domain creation if no ASIDs are free.

Join the discussion
0

The ITE IT8xxx2 SHI host-command backend (subsys/mgmt/ec_host_cmd/backends/ec_host_cmd_backend_shi_ite.c) copied the 8-byte host-command request header from the SPI Rx FIFO directly into the shared receive buffer data->in_msg and only afterwards checked the protocol version and the derived packet length. The interrupt handler also accepted a chip-select assertion and an Rx-valid-length (RVLI) interrupt in any driver state other than SHI_STATE_DISABLED, so a new header could be parsed while the host-command thread was still processing the previous request out of the very same buffer. The host processor is the SPI controller and drives both chip select and the clock. After sending a well-formed request it can immediately de-assert chip select — which returns the driver to the ready state and re-enables the FIFO — and start a second transaction carrying a header with data_len = 0xFFFF. Those eight bytes are written into in_msg before the oversized length is rejected, so they land in a buffer whose contents verify_rx() in subsys/mgmt/ec_host_cmd/ec_host_cmd_handler.c has already validated. If this lands in the window before the host-command thread executes args.input_buf_size = rx_header->data_len, the framework hands the registered command handler a 65535-byte input length over a 256-byte buffer. The result is an out-of-bounds read of up to roughly 64 KiB beyond the request buffer: command handlers that copy or echo input_buf_size bytes disclose adjacent embedded-controller memory back to the host or overflow the response buffer, and a read past the end of SRAM faults the controller. The same race also allows cmd_id and cmd_ver to be swapped after checksum verification and after handler lookup. Exploitation requires the ability to drive the inter-processor SHI bus (a compromised host OS or physical access to the SPI lines) and winning a timing race, which the SPI controller can retry indefinitely. The fix parses the header into a local struct ec_host_cmd_request_header and copies it into in_msg only after the length has been bounded by sizeof(data->in_msg), and ignores chip-select and RVLI interrupts outside SHI_STATE_READY_TO_RECV/SHI_STATE_RECEIVING. A residual, bounded race remains: an end-of-transaction interrupt still resets the state to ready while the host-command thread owns the buffer, so a valid second request can still overwrite the in-flight request's contents, unlike the NPCX backend which parks in SHI_STATE_CNL_RESP_NOT_RDY while the buffer is in use.

Join the discussion
0

CVE-2026-19570 is a memory safety vulnerability in the Zephyr project's Bluetooth LE Audio Broadcast Sink implementation. The flaw allows an attacker within radio range to send a crafted Basic Audio Announcement (BASE) that causes out-of-bounds memory writes and potential memory disclosure due to lack of bounds checking when copying subgroup metadata. This can lead to memory corruption and possibly remote code execution without requiring pairing or bonding. The vulnerability affects Zephyr versions from 3.6.0 up to and including 4.4.2. A fix has been implemented to reject BASE data with too many subgroups and to omit metadata that does not fit, preventing the overflow.

Join the discussion

CVE-2026-106155 is a stored cross-site scripting (XSS) vulnerability in Progress Software's Telerik Report Server before version 12.2.26.1007. It allows an authenticated report author to embed malicious script URLs in report navigation actions or HTML text box links. When other users view and trigger these links, the attacker-controlled scripts execute in the context of the web report viewer. This can lead to privilege escalation by performing actions in the session of a higher-privileged user, including administrators.

Join the discussion

In Progress® Telerik® Report Server prior to version 12.2.26.1007, incorrect privilege assignment in the service-agent SignalR hub allows an authenticated user, including a low-privilege or guest account with a valid bearer token, to register as a trusted service agent. On the next server settings-synchronization event, the rogue agent receives storage settings and encryption private keys. This privilege escalation enables disclosure of protected secrets, including stored data-source credentials and connection strings, and allows agent impersonation and interference with task dispatch.

Join the discussion

CVE-2026-101028 is an incorrect authorization vulnerability in the ash-project ash framework that allows an attacker with limited privileges to infer data from related records they should not be able to access. The flaw arises because aggregate queries via Ash.Actions.Aggregate.run/4 apply only the root resource's read policy and skip applying read policies on related resources. This enables an attacker to test conditions on hidden related rows using functions like Ash.count/2, Ash.exists/2, and Ash.aggregate/3, thereby revealing existence and attribute values one query at a time. The vulnerability affects ash versions from 2.6.0 up to but not including 3.34.6. The issue does not affect Ash.read/2 or its page counts. The CVSS 4.0 score is 6.0, indicating a medium severity.

Join the discussion

CVE-2026-97076 is a vulnerability in WP Media's WP Rocket plugin that involves an executable regular expression error allowing code injection. It affects versions from initial releases up to but not including 3.23.5. The vulnerability has a high severity score of 7.5 and can cause denial of service conditions. No known exploits are reported in the wild, and no official patch information is provided in the input data.

Join the discussion
0

CVE-2026-107406 is a critical memory overflow vulnerability in NetScaler ADC and NetScaler Gateway when configured as a SAML Service Provider (SP) or Identity Provider (IdP). This flaw can lead to remote code execution or denial of service. It affects multiple versions of NetScaler ADC and Gateway, specifically versions before 14.1-73.46 and 13.1-64.29, including certain FIPS variants. The vulnerability has a high CVSS 4.0 score of 9.5, indicating severe impact if exploited.

Join the discussion

Showing 1 to 10 of 146496 results

Filters:Package: pkg:bitnami/consul
Page 1 of 14650
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses