Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
CVE-2026-73542: Improper Following of a Certificate's Chain of Trust in SEIKO EPSON CORPORATION Multiple SEIKO EPSON printers and scannersCVE-2026-73542 0 Multiple SEIKO EPSON printers and scanners contain revoked root certificates. A man-in-the-middle attack may allow an attacker to obtain communication data transmitted by the product. As for the details of the affected products and versions, refer to the vendor's information. Join the discussion | CVE Database V5 | 08/20/2026, 05:16:14 UTC Added: 08/20/2026, 05:22:53 UTC |
Multiple SEIKO EPSON printers and scanners keep already revoked root certificates 0 Multiple SEIKO EPSON printers and scanners contain root certificates that have already been revoked. This means these devices retain trust anchors that are no longer valid, potentially undermining the security of certificate validation processes. No specific affected versions or patch information is provided. MediumVulnerability Join the discussion | JVN Japan | 08/20/2026, 05:00:00 UTC Added: 08/20/2026, 05:15:18 UTC |
CVE-2026-16885: CWE-121 Stack-based Buffer Overflow in IBM AIXCVE-2026-16885 0 CVE-2026-16885 is a critical stack-based buffer overflow vulnerability affecting IBM AIX versions 7.2 and 7.3, as well as IBM PowerVM VIOS 4.1. This flaw could allow a remote attacker to execute arbitrary code without requiring user interaction or privileges. The vulnerability has a CVSS score of 9.8, indicating a high impact on confidentiality, integrity, and availability. No official patch or remediation information is currently available. Join the discussion | CVE Database V5 | 08/19/2026, 19:51:05 UTC Added: 08/20/2026, 04:07:55 UTC |
BlackHat Arsenal Lab02 0 BlackHat Arsenal Lab02 is an open-source, hands-on cybersecurity training lab presented at Black Hat USA 2026. It includes two scenarios focused on cloud security and incident response, using synthetic data and AI-driven tooling to teach skills such as detecting SSRF attacks, credential leaks, IAM enumeration, S3 exfiltration, and cloud configuration auditing. The lab is designed for educational purposes and does not represent an active security threat or vulnerability. Join the discussion | Reddit Cybersecurity | 08/20/2026, 02:59:25 UTC Added: 08/20/2026, 03:52:03 UTC |
CVE-2026-76800: Unrestricted Upload in DeDeCMSCVE-2026-76800 0 CVE-2026-76800 is a medium severity vulnerability in DeDeCMS 3 involving an unrestricted file upload flaw in the /include/dialog/select_media_post.php component. The vulnerability allows remote attackers to manipulate the uploadfile argument to upload files without restriction. Exploit code has been published, but no official patch or remediation guidance is currently available. Join the discussion | CVE Database V5 | 08/20/2026, 02:00:43 UTC Added: 08/20/2026, 02:22:45 UTC |
ISC Stormcast For Thursday, August 20th, 2026 https://isc.sans.edu/podcastdetail/10060, (Thu, Aug 20th) 0 This entry references the ISC Stormcast podcast episode from August 20th, 2026, published by the SANS Internet Storm Center. The content is a security news update without specific details about any particular vulnerability, exploit, or threat. No technical or actionable threat information is provided. LowNews Join the discussion | SANS ISC Handlers Diary | 08/20/2026, 02:00:03 UTC Added: 08/20/2026, 02:07:11 UTC |
CVE-2026-76799: Files or Directories Accessible in code-projects Login Registration SystemCVE-2026-76799 0 CVE-2026-76799 is a medium severity vulnerability in code-projects Login Registration System version 1.0. It involves a weakness in the SQL Database Backup Handler component, specifically related to the file /loginsystem/database/login_registration_system.sql. This flaw allows remote attackers to access files or directories improperly. The vulnerability has a CVSS 4.0 base score of 6.9 and public exploit code is available. No official patch or remediation guidance has been provided by the vendor as of the publication date. Join the discussion | CVE Database V5 | 08/20/2026, 01:15:10 UTC Added: 08/20/2026, 01:52:53 UTC |
CVE-2026-76795: Server-Side Request Forgery in AeternaLabsHQ PullMDCVE-2026-76795 0 CVE-2026-76795 is a server-side request forgery (SSRF) vulnerability in AeternaLabsHQ PullMD version 3.2.0. The flaw exists in the REST API endpoint at /api, where manipulation of the 'url' argument allows an attacker to induce the server to make unintended requests. This vulnerability can be exploited remotely without authentication. A public exploit disclosure exists. Upgrading to version 3.3.0 resolves the issue. Join the discussion | CVE Database V5 | 08/20/2026, 00:45:12 UTC Added: 08/20/2026, 01:22:45 UTC |
CVE-2026-76785: SQL Injection in amirsanni Mini-Inventory-and-Sales-Management-SystemCVE-2026-76785 0 CVE-2026-76785 is a medium severity SQL injection vulnerability in amirsanni Mini-Inventory-and-Sales-Management-System version 0.1. The flaw exists in the Transaction::getAll function within application/models/Transaction.php, where manipulation of the orderBy or orderFormat arguments can lead to SQL injection. The vulnerability can be exploited remotely without user interaction. Although the issue was reported early to the project, no response or fix has been provided yet. Public exploit code is available, increasing the risk of exploitation. Join the discussion | CVE Database V5 | 08/20/2026, 00:30:10 UTC Added: 08/20/2026, 00:52:39 UTC |
CVE-2026-75628: CWE-601 URL Redirection to Untrusted Site ('Open Redirect')CVE-2026-75628 0 Punk::OAuth2 versions before 0.03 for Perl allow an attacker-chosen off-site redirect after login because same_origin_path accepts a backslash or tab in the return parameter. oauth2_login reads the return parameter from the initiation request, runs same_origin_path over it, and stores the survivor in the session flow record as the post-login redirect target. That check rejects a value that does not begin with a slash, one with a slash as its second byte, and one containing CR or LF. A backslash and a tab pass. The URL Standard treats a backslash as equivalent to a slash for special schemes, so `/\evil.example` parses with the authority `evil.example`. It also strips ASCII tab before parsing, so a tab between two leading slashes leaves `//evil.example`. A crafted link to the application's own login route lands the victim on the attacker's site after a genuine authentication. The redirect carries no authorization code or access token. Join the discussion | CVE Database V5 | 08/20/2026, 00:40:08 UTC Added: 08/20/2026, 00:52:39 UTC |
Showing 1 to 10 of 19929 results