Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
UNIVERGE IX-R/IX-V series routers vulnerable to missing authentication for critical function 0 NEC Corporation's UNIVERGE IX-R/IX-V series routers have a vulnerability involving missing authentication for a critical function. This security flaw could allow unauthorized access to sensitive router functions. No specific affected versions or patch information is provided. There is no evidence of known exploits in the wild at this time. HighVulnerability Join the discussion | JVN Japan | 08/21/2026, 05:00:00 UTC Added: 08/21/2026, 05:08:31 UTC |
CVE-2026-45202: CWE-415: Double Free in Imagination Technologies Graphics DDKCVE-2026-45202 0 CVE-2026-45202 is a double free vulnerability in the Imagination Technologies Graphics DDK. It occurs when software running as a non-privileged user makes GPU system calls that lead to GPU memory leaks and potential kernel heap corruption. The issue arises from memory free paths that do not maintain state data of upgraded higher order allocations, causing either memory leaks or double free events. No patch or official remediation has been confirmed yet. There are no known exploits in the wild at this time. Join the discussion | CVE Database V5 | 08/21/2026, 04:09:15 UTC Added: 08/21/2026, 04:23:21 UTC |
CVE-2026-45201: CWE-1284: Improper Validation of Specified Quantity in Input in Imagination Technologies Graphics DDKCVE-2026-45201 0 CVE-2026-45201 is a vulnerability in Imagination Technologies Graphics DDK where improper validation of a specified log2 page size during GPU system calls can lead to out-of-bounds (OOB) memory read or write. This occurs when software running as a non-privileged user passes an invalid log2 page size, causing 4K pages to be treated as higher order pages and allowing access beyond the intended memory boundary. Join the discussion | CVE Database V5 | 08/21/2026, 04:01:04 UTC Added: 08/21/2026, 04:23:21 UTC |
CVE-2026-45199: CWE-823: Use of Out-of-range Pointer Offset (4.16) in Imagination Technologies Graphics DDKCVE-2026-45199 0 CVE-2026-45199 is a vulnerability in Imagination Technologies Graphics DDK where kernel software running inside a Guest VM can issue commands to the GPU firmware that cause writes outside the Guest's virtualized GPU memory. This out-of-bounds memory access can be exploited to escalate privileges within the virtualized environment. Join the discussion | CVE Database V5 | 08/21/2026, 03:36:39 UTC Added: 08/21/2026, 04:07:59 UTC |
CVE-2026-18409: CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in WPForms WPForms ProCVE-2026-18409 0 WPForms Pro plugin for WordPress up to version 2.0.0.2 is vulnerable to stored cross-site scripting (XSS) via Single Line Text and Paragraph Text fields. The vulnerability arises from insufficient input sanitization and output escaping, allowing unauthenticated attackers to inject arbitrary scripts. The exploit abuses the plugin's wp_kses_allowed_html filter to permit iframe elements with a data-src attribute, which can contain a javascript: URI that bypasses WordPress's sanitization and executes in the context of users viewing the injected page. Join the discussion | CVE Database V5 | 08/21/2026, 03:37:48 UTC Added: 08/21/2026, 04:07:59 UTC |
Miraikan Assist App vulnerable to cross-site scripting 0 The Miraikan Assist App, developed by the Japan Science and Technology Agency (JST), contains a cross-site scripting (XSS) vulnerability. This type of vulnerability allows attackers to inject malicious scripts into web pages viewed by other users. No specific affected versions or patch information have been provided. There is no evidence of active exploitation in the wild at this time. Join the discussion | JVN Japan | 08/21/2026, 03:00:00 UTC Added: 08/21/2026, 03:08:03 UTC |
CVE-2026-73267: Client-Side Enforcement of Server-Side Security in Red Hat Multicluster Engine for KubernetesCVE-2026-73267 0 CVE-2026-73267 is a high-severity vulnerability in the clusterclaims-controller component of Red Hat Multicluster Engine for Kubernetes. It allows a tenant with standard permissions on ClusterClaim resources to manipulate the spec.namespace field to delete any ManagedCluster, including critical clusters such as the hub's local-cluster or other tenants' clusters. This occurs due to a missing ownership check, leading to potential denial of service by unauthorized deletion of ManagedClusters. Currently, no effective mitigation or official fix meeting Red Hat's criteria is available. Join the discussion | CVE Database V5 | 08/21/2026, 02:43:36 UTC Added: 08/21/2026, 02:52:54 UTC |
CVE-2026-76158: CWE-73 External control of file name or path in Datiphy Inc. Data Management CenterCVE-2026-76158 0 CVE-2026-76158 is a critical vulnerability in Datiphy Inc.'s Data Management Center affecting version 8.3.0. It involves external control of file name or path in the upload API endpoint, allowing remote attackers to write files to arbitrary locations outside the intended upload directory by using relative or absolute path sequences. Join the discussion | CVE Database V5 | 08/21/2026, 02:02:23 UTC Added: 08/21/2026, 02:37:50 UTC |
CVE-2026-76137: Missing authentication for critical function in Yamaha Corporation VOCALOID6CVE-2026-76137 0 A vulnerability in Yamaha Corporation's VOCALOID6 allows local privilege escalation due to missing authentication on a critical function. This flaw enables any process running under the same local user account as the VOCALOID6 Editor to escalate privileges via a local named pipe. The vulnerability has a low CVSS score of 3.3, indicating limited impact primarily on confidentiality. No official patch or remediation guidance is currently available. Join the discussion | CVE Database V5 | 08/21/2026, 02:02:54 UTC Added: 08/21/2026, 02:37:50 UTC |
CVE-2026-76131: Use of hard-coded credentials in Yamaha Corporation VOCALOID6CVE-2026-76131 0 CVE-2026-76131 is a medium severity vulnerability in Yamaha Corporation's VOCALOID6 software involving the use of hard-coded credentials. This flaw may allow an attacker to impersonate a legitimate VOCALOID6 Editor and gain unauthorized access to Yamaha's activation and content servers. No specific affected versions or patches are currently documented. Join the discussion | CVE Database V5 | 08/21/2026, 02:02:44 UTC Added: 08/21/2026, 02:37:50 UTC |
Showing 1 to 10 of 18121 results