Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

UNIVERGE IX-R/IX-V series routers vulnerable to missing authentication for critical function
0

NEC Corporation's UNIVERGE IX-R/IX-V series routers have a vulnerability involving missing authentication for a critical function. This security flaw could allow unauthorized access to sensitive router functions. No specific affected versions or patch information is provided. There is no evidence of known exploits in the wild at this time.

HighVulnerability
Join the discussion
CVE-2026-45202: CWE-415: Double Free in Imagination Technologies Graphics DDKCVE-2026-45202
0

CVE-2026-45202 is a double free vulnerability in the Imagination Technologies Graphics DDK. It occurs when software running as a non-privileged user makes GPU system calls that lead to GPU memory leaks and potential kernel heap corruption. The issue arises from memory free paths that do not maintain state data of upgraded higher order allocations, causing either memory leaks or double free events. No patch or official remediation has been confirmed yet. There are no known exploits in the wild at this time.

Join the discussion
CVE-2026-45201: CWE-1284: Improper Validation of Specified Quantity in Input in Imagination Technologies Graphics DDKCVE-2026-45201
0

CVE-2026-45201 is a vulnerability in Imagination Technologies Graphics DDK where improper validation of a specified log2 page size during GPU system calls can lead to out-of-bounds (OOB) memory read or write. This occurs when software running as a non-privileged user passes an invalid log2 page size, causing 4K pages to be treated as higher order pages and allowing access beyond the intended memory boundary.

Join the discussion
CVE-2026-45199: CWE-823: Use of Out-of-range Pointer Offset (4.16) in Imagination Technologies Graphics DDKCVE-2026-45199
0

CVE-2026-45199 is a vulnerability in Imagination Technologies Graphics DDK where kernel software running inside a Guest VM can issue commands to the GPU firmware that cause writes outside the Guest's virtualized GPU memory. This out-of-bounds memory access can be exploited to escalate privileges within the virtualized environment.

Join the discussion
CVE-2026-18409: CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in WPForms WPForms ProCVE-2026-18409
0

WPForms Pro plugin for WordPress up to version 2.0.0.2 is vulnerable to stored cross-site scripting (XSS) via Single Line Text and Paragraph Text fields. The vulnerability arises from insufficient input sanitization and output escaping, allowing unauthenticated attackers to inject arbitrary scripts. The exploit abuses the plugin's wp_kses_allowed_html filter to permit iframe elements with a data-src attribute, which can contain a javascript: URI that bypasses WordPress's sanitization and executes in the context of users viewing the injected page.

Join the discussion
Miraikan Assist App vulnerable to cross-site scripting
0

The Miraikan Assist App, developed by the Japan Science and Technology Agency (JST), contains a cross-site scripting (XSS) vulnerability. This type of vulnerability allows attackers to inject malicious scripts into web pages viewed by other users. No specific affected versions or patch information have been provided. There is no evidence of active exploitation in the wild at this time.

MediumVulnerability#xss
Join the discussion
CVE-2026-73267: Client-Side Enforcement of Server-Side Security in Red Hat Multicluster Engine for KubernetesCVE-2026-73267
0

CVE-2026-73267 is a high-severity vulnerability in the clusterclaims-controller component of Red Hat Multicluster Engine for Kubernetes. It allows a tenant with standard permissions on ClusterClaim resources to manipulate the spec.namespace field to delete any ManagedCluster, including critical clusters such as the hub's local-cluster or other tenants' clusters. This occurs due to a missing ownership check, leading to potential denial of service by unauthorized deletion of ManagedClusters. Currently, no effective mitigation or official fix meeting Red Hat's criteria is available.

Join the discussion
CVE-2026-76158: CWE-73 External control of file name or path in Datiphy Inc. Data Management CenterCVE-2026-76158
0

CVE-2026-76158 is a critical vulnerability in Datiphy Inc.'s Data Management Center affecting version 8.3.0. It involves external control of file name or path in the upload API endpoint, allowing remote attackers to write files to arbitrary locations outside the intended upload directory by using relative or absolute path sequences.

Join the discussion
CVE-2026-76137: Missing authentication for critical function in Yamaha Corporation VOCALOID6CVE-2026-76137
0

A vulnerability in Yamaha Corporation's VOCALOID6 allows local privilege escalation due to missing authentication on a critical function. This flaw enables any process running under the same local user account as the VOCALOID6 Editor to escalate privileges via a local named pipe. The vulnerability has a low CVSS score of 3.3, indicating limited impact primarily on confidentiality. No official patch or remediation guidance is currently available.

Join the discussion
CVE-2026-76131: Use of hard-coded credentials in Yamaha Corporation VOCALOID6CVE-2026-76131
0

CVE-2026-76131 is a medium severity vulnerability in Yamaha Corporation's VOCALOID6 software involving the use of hard-coded credentials. This flaw may allow an attacker to impersonate a legitimate VOCALOID6 Editor and gain unauthorized access to Yamaha's activation and content servers. No specific affected versions or patches are currently documented.

Join the discussion

Showing 1 to 10 of 18121 results

Filters:Package: pkg:bitnami/mastodon
Page 1 of 1813
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses