Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

CVE-2026-19771: OS Command Injection in Baicells EG3661MCVE-2026-19771
0

A vulnerability was identified in Baicells EG3661M BaiCE_BQ6_2.0.5.3_NA. This impacts an unknown function of the file /cgi-bin/luci of the component LuCI Web Interface. Such manipulation of the argument MaxHops/Timeout/Size leads to os command injection. The attack may be launched remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.

Join the discussion
CVE-2026-19770: Server-Side Request Forgery in feedmob fm-mcp-serversCVE-2026-19770
0

A vulnerability was identified in feedmob fm-mcp-servers 0.0.3. Affected by this vulnerability is the function downloadReport of the file src/smadex-reporting/src/index.ts of the component Download Endpoint. The manipulation of the argument downloadUrl leads to server-side request forgery. The attack can only be performed from a local environment. The exploit is publicly available and might be used. The project was informed of the problem early through an issue report but has not responded yet.

Join the discussion
CVE-2026-19767: SQL Injection in itsourcecode Hospital Management SystemCVE-2026-19767
0

A weakness has been identified in itsourcecode Hospital Management System 1.0. This issue affects some unknown processing of the file viewdoctortimings.php. Executing a manipulation of the argument delid can lead to sql injection. The attack may be performed from remote. The exploit has been made available to the public and could be used for attacks.

Join the discussion
ISC Stormcast For Friday, August 14th, 2026 https://isc.sans.edu/podcastdetail/10052, (Fri, Aug 14th)
0

This entry references the ISC Stormcast podcast episode for August 14th, 2026, published by the SANS Internet Storm Center. The content is a security news update without specific details about any security threat or vulnerability.

LowNews
Join the discussion
New LAB - Damn Vulnerable NGINX Proxy
0

Damn Vulnerable NGINX Proxy (DVNP) is a self-contained web security lab published by OWASP that simulates a multi-host NGINX reverse-proxy environment with over 20 real-world misconfigurations. It is designed for security professionals to practice identifying and exploiting chained web and reverse-proxy misconfigurations in a controlled setting. This lab includes backend Flask applications and shared resources to provide a realistic environment for pentesting and bug bounty training. It is not a vulnerability itself but a training tool to improve skills in finding NGINX-related security issues.

Join the discussion
CVE-2026-19765: Server-Side Request Forgery in eyaushev swagger-testcase-mcpCVE-2026-19765
0

CVE-2026-19765 is a server-side request forgery (SSRF) vulnerability in the eyaushev swagger-testcase-mcp project. It affects the loadSource function in the src/utils/swagger-parser.ts file within the fetch_swagger component. The vulnerability allows remote attackers to manipulate requests, potentially causing the server to make unintended requests. The project uses a rolling release model, so specific affected versions are not identified. The issue was reported early to the project, but no response or patch has been provided yet. The CVSS 4.0 score rates this vulnerability as medium severity.

Join the discussion
CVE-2026-19764: SQL Injection in Raisecom Communication Command and Dispatch Management PlatformCVE-2026-19764
0

CVE-2026-19764 is a medium severity SQL injection vulnerability in Raisecom Communication Command and Dispatch Management Platform versions 7.6.0 through 7.6.5. The flaw exists in the /app/users/getpwd.php file where the 'sip' argument can be manipulated to perform SQL injection remotely. The vendor has not responded to disclosure attempts, and no official patch or remediation guidance is currently available. Exploit code is publicly available, but no known exploitation in the wild has been reported.

Join the discussion
Apple sends new ‘Threat Notification’ alerts over mercenary spyware attacks
0

Apple has been sending 'Threat Notification' alerts to users since 2021 when it detects highly targeted mercenary spyware attacks on iPhones. These alerts indicate a high-confidence suspicion that the user was individually targeted by sophisticated spyware, such as NSO Group's Pegasus, though Apple does not specify the spyware involved in each alert. The notifications are sent via email, iMessage, and appear on the user's Apple account page. Apple recommends taking these alerts seriously and enabling Lockdown Mode if affected. These attacks are rare, expensive, and typically target high-profile individuals like journalists, activists, and diplomats.

HighNews
Join the discussion
CVE-2026-19763: Path Traversal in DTStack TaierCVE-2026-19763
0

CVE-2026-19763 is a path traversal vulnerability in DTStack Taier version 1.4.0. It affects the FileUtils.deleteDirectory function in the ClusterController.java file, specifically in the Cluster Creation component. The vulnerability allows remote attackers with high privileges to manipulate the clusterName argument to perform path traversal. Upgrading to version 1.5.0 resolves this issue.

Join the discussion
CVE-2026-19762: Path Traversal in DTStack TaierCVE-2026-19762
0

CVE-2026-19762 is a path traversal vulnerability in DTStack Taier version 1.4.0. It affects the Paths.ge function in the FileChunkController.java file within the Chunk-Check Endpoint component. The vulnerability allows remote attackers to manipulate the 'Name' argument to perform path traversal. An exploit for this vulnerability has been publicly disclosed. The vulnerability has a CVSS 4.0 base score of 6.9, indicating medium severity.

Join the discussion

Showing 1 to 10 of 23942 results

Filters:Package: pkg:bitnami/haproxy
Page 1 of 2395
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses