Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
CVE-2026-76198: Improper Input Validation (CWE-20) in Adobe C2PA ToolCVE-2026-76198 0 CAI Content Credentials is affected by an Improper Input Validation vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access sensitive files and directories outside the intended access scope. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Join the discussion | CVE Database V5 | 08/25/2026, 17:31:26 UTC Added: 08/25/2026, 17:37:43 UTC |
CVE-2026-76197: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') (CWE-78) in Adobe Adobe Campaign ClassicCVE-2026-76197 0 Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed. Join the discussion | CVE Database V5 | 08/25/2026, 17:27:10 UTC Added: 08/25/2026, 17:37:41 UTC |
CVE-2026-76195: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') (CWE-78) in Adobe Adobe Campaign ClassicCVE-2026-76195 0 Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed. Join the discussion | CVE Database V5 | 08/25/2026, 17:27:11 UTC Added: 08/25/2026, 17:37:41 UTC |
CVE-2026-76193: Server-Side Request Forgery (SSRF) (CWE-918) in Adobe Adobe Campaign ClassicCVE-2026-76193 0 Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed. Join the discussion | CVE Database V5 | 08/25/2026, 17:27:10 UTC Added: 08/25/2026, 17:37:41 UTC |
CVE-2026-76189: Integer Underflow (Wrap or Wraparound) (CWE-191) in Adobe C2PA ToolCVE-2026-76189 0 CAI Content Credentials is affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue does not require user interaction. Join the discussion | CVE Database V5 | 08/25/2026, 17:31:29 UTC Added: 08/25/2026, 17:37:41 UTC |
CVE-2026-71444: Integer Underflow (Wrap or Wraparound) (CWE-191) in Adobe C2PA ToolCVE-2026-71444 0 CAI Content Credentials is affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue does not require user interaction. Join the discussion | CVE Database V5 | 08/25/2026, 17:31:27 UTC Added: 08/25/2026, 17:37:41 UTC |
CVE-2026-71443: Improper Input Validation (CWE-20) in Adobe C2PA ToolCVE-2026-71443 0 CAI Content Credentials is affected by an Improper Input Validation vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue does not require user interaction. Join the discussion | CVE Database V5 | 08/25/2026, 17:31:29 UTC Added: 08/25/2026, 17:37:41 UTC |
CVE-2026-71442: Integer Underflow (Wrap or Wraparound) (CWE-191) in Adobe C2PA ToolCVE-2026-71442 0 CAI Content Credentials is affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue does not require user interaction. Join the discussion | CVE Database V5 | 08/25/2026, 17:31:28 UTC Added: 08/25/2026, 17:37:41 UTC |
CVE-2026-71360: Uncontrolled Resource Consumption (CWE-400) in Adobe C2PA ToolCVE-2026-71360 0 CAI Content Credentials is affected by an Uncontrolled Resource Consumption vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerability to exhaust system resources, resulting in an application denial-of-service condition. Exploitation of this issue does not require user interaction. Join the discussion | CVE Database V5 | 08/25/2026, 17:31:27 UTC Added: 08/25/2026, 17:37:41 UTC |
CVE-2026-55419: CWE-434: Unrestricted Upload of File with Dangerous Type in pollen-robotics reachy_miniCVE-2026-55419 0 Reachy Mini is an SDK for controlling Reachy Mini robots. Prior to 1.8.2, the Reachy Mini daemon exposes the /api/media/sounds/upload endpoint implemented by the upload_sound method in src/reachy_mini/daemon/app/routers/media.py without authentication, file-extension checks, content validation, or size validation. The daemon binds to 0.0.0.0 by default and uses permissive CORS allow_origins=["*"], allowing an unauthenticated network attacker to upload arbitrary file types that are written to /tmp/reachy_mini_sounds/<original_filename>. Malicious files can compromise stored-data integrity and can serve as a foothold when combined with other vulnerabilities. This issue is fixed in version 1.8.2. Join the discussion | CVE Database V5 | 08/25/2026, 17:34:58 UTC Added: 08/25/2026, 17:37:41 UTC |
Showing 1 to 10 of 18239 results