Skip to main content

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Package: pkg:bitnami/mastodon

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

The alleged leader of the ShinyHunters extortion group, a teenage cybercriminal known as Rey (Saif al-Din Khader), was arrested in Jordan and is cooperating with the FBI to identify other members. The arrest followed a recent hack and defacement of the FBI's jobs site, with ShinyHunters claiming to have stolen terabytes of data including personal and health information of FBI employees. The FBI confirmed the group hacked over 140 organizations and extorted at least $70 million. Another suspect was arrested in the Netherlands as part of the investigation. The FBI continues to pursue additional leads and anticipates more arrests.

HighNews
Join the discussion
0

A security flaw has been discovered in vgmstream up to r2117. This affects the function parse_params/txtp_parse of the file src/meta/txtp_parser.c of the component TXTP File Handler. The manipulation results in out-of-bounds write. The attack may be launched remotely. The patch is identified as 4669d37a6af94866f6f0628678f9f90d46954e8b. It is best practice to apply a patch to resolve this issue.

Join the discussion

A vulnerability was determined in SourceCodester Online Reviewer Management System 1.0. The affected element is an unknown function of the file /reviewer_0/admins/assessments/Subject/btn_functions.php?action=course. Executing a manipulation of the argument Subject can lead to sql injection. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized.

Join the discussion

Net::Whois::Raw versions before 2.99044 for Perl include a pwhois command-line tool that incorrectly handles Unicode domain names. The tool encodes non-ASCII labels using Net::IDN::Punycode but skips important IDNA mapping and normalization steps, causing it to query WHOIS for incorrect domain names. This affects domain labels with uppercase letters outside ASCII and Cyrillic or labels not in NFC normalization form. The core Net::Whois::Raw library modules are not affected.

Join the discussion

CVE-2026-105246 is a SQL injection vulnerability in SourceCodester Online Reviewer Management System version 1.0. It occurs in the file /reviewer_0/admins/assessments/Subject/btn_functions.php?action=update when the Subject argument is manipulated. The vulnerability allows remote attackers to inject SQL commands. The exploit code has been publicly disclosed. The CVSS 4.0 base score is 6.9, indicating a medium severity level.

Join the discussion

CVE-2026-100727 is an improper access control vulnerability in GROWI that allows unauthenticated attackers to read files in non-public pages when the file upload setting is configured as "Local." This vulnerability affects versions from 0 up to but not including 7.5.5. The CVSS 3.0 score is 5.3, indicating a medium severity impact with confidentiality loss but no integrity or availability impact.

Join the discussion

CVE-2026-105245 is a medium severity vulnerability in sgl-project sglang up to version 0.5.21. It involves the cleartext transmission of sensitive information via the api_key argument in the HTTP Endpoint component. The vulnerability can be exploited remotely but requires a high level of attack complexity. A fix has been proposed but is pending acceptance.

Join the discussion

CVE-2026-105238 is a server-side request forgery (SSRF) vulnerability in ChatGPTNextWeb NextChat versions 2.16.0 and 2.16.1. The flaw exists in the proxyHandler function of the app/api/proxy.ts file, specifically in the Proxy Fallback Handler component. An attacker can remotely manipulate the x-base-url argument to induce SSRF. An exploit has been published, and a fix is pending acceptance in a pull request.

Join the discussion

A vulnerability in the File Uploads Addon for WooCommerce WordPress plugin before version 1.7.6 allows unauthorized users to download files uploaded by other customers. This occurs because the plugin does not verify that the requester is the original uploader of the file, enabling authorization bypass via user-controlled keys.

Join the discussion

The File Uploads Addon for WooCommerce WordPress plugin versions 1.7.2 through 1.7.6 improperly restricts access to customer-uploaded files. These files are stored in a publicly accessible directory, and the plugin's access control mechanism can be bypassed by unauthenticated attackers who know or guess the file names, allowing direct retrieval of uploaded files.

Join the discussion

Showing 1 to 10 of 144183 results

Filters:Package: pkg:bitnami/mastodon
Page 1 of 14419
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses