Skip to main content

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Package: pkg:bitnami/mlflow

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

Multiple vulnerabilities have been identified in Movable Type provided by Six Apart Ltd. No specific technical details, affected versions, or exploit information are available in the provided data.

MediumVulnerability
Join the discussion
0

Red Hat has issued a security advisory for an update to Red Hat Hardened Images RPMs, specifically addressing a vulnerability identified as CVE-2026-19445. The update includes multiple python3.15 packages for aarch64 and x86_64 architectures. The advisory does not specify detailed technical information about the vulnerability but categorizes it as high severity and related to CWE-416 (Use After Free). No explicit fix version or patch details are provided in the advisory.

Join the discussion

CVE-2026-19572 is a critical authentication bypass vulnerability in Flexera FlexNet Publisher lmadmin. It involves a hardcoded bypass in a SOAP handler that allows unauthenticated users to gain privileged administrator sessions without valid credentials. This affects versions from 0 up to and including 11.19.11. The vulnerability has a high CVSS 4.0 score of 9.3, indicating severe impact. No patch information is provided, and no known exploits are reported in the wild.

Join the discussion

Keyence Corporation's XG VisionTerminal and XG-X VisionTerminal products have a vulnerability related to improper restriction of XML external entity (XXE) references. This vulnerability could allow an attacker to exploit XML processing in these devices. No specific affected versions or patch information is provided, and there is no evidence of active exploitation in the wild.

MediumVulnerability
Join the discussion
0

Multiple security issues were fixed in the glibc-2.44-1.1 package for openSUSE Tumbleweed. These issues relate to vulnerabilities identified by CWE-1341 and CWE-120. The update addresses these flaws to improve security. The vendor advisory from Red Hat indicates that updates are available for related packages, including glibc and its language packs. No known exploits are reported in the wild. The severity is assessed as medium.

Join the discussion

CVE-2026-84897 is a medium severity vulnerability in wolfSSL wolfSSH versions 1.2.0 through before 1.6.0. It involves improper handling of Diffie-Hellman group exchange messages on the server side, allowing unauthenticated clients to send certain key exchange messages that the server incorrectly accepts. This leads the server to perform expensive primality tests and generate key pairs based on attacker-supplied parameters. Builds that disable DH GEX SHA256 are not affected.

Join the discussion

CVE-2026-83742 is an integer underflow vulnerability in wolfSSL wolfSSH versions 1.4.11 through before 1.6.0 on non-Windows platforms. It occurs in the wstrncat() function in src/port.c, where an authenticated remote attacker can cause a single null byte to be written just past the end of a stack buffer by sending a specially crafted SFTP path. This can corrupt adjacent stack memory and potentially crash the process. The vulnerability arises from incorrect size calculations leading to an unbounded string concatenation. The overflow is limited to one null byte, and no known exploits are reported in the wild.

Join the discussion

CVE-2026-83540 is a high-severity improper authentication vulnerability in the Windows port of wolfSSHd, part of wolfSSL's wolfSSH product. The flaw causes the Windows logon token from one authenticated connection to not be released before a new token is acquired for a subsequent connection. This leads to user login poisoning between connections, allowing a less privileged user with a valid account to escalate privileges by forcing a login as a more privileged user. The vulnerability affects wolfSSH versions from 1.4.15 up to but not including 1.6.0. Non-Windows builds are not impacted.

Join the discussion

CVE-2026-81535 is a missing authorization vulnerability in wolfSSH versions 1.4.8 up to but not including 1.6.0. The issue occurs when wolfSSH is built with the --enable-fwd option. The function DoChannelOpen() only enforces authorization checks on direct-tcpip channel opens, but forwarded-tcpip channel opens bypass these checks and are not limited in number. This allows a malicious SSH peer to cause unbounded memory allocation on the endpoint. Additionally, the client does not verify forwarded-tcpip opens against registered tcpip-forward requests as required by RFC 4254 section 7.2, enabling a malicious server to open forwarding channels for unauthorized addresses and ports.

Join the discussion

wolfSSH contains a vulnerability where it does not verify that the ECDSA curve identifier in a host key blob matches the algorithm negotiated during key exchange. This allows an active man-in-the-middle attacker to substitute a host key blob with a different ECDSA curve, causing the client to import the key on the wrong curve and accept a malicious key. Exploitation requires an active MitM position and a lax public key check callback. The vulnerability affects wolfSSH versions prior to 1.6.0.

Join the discussion

Showing 1 to 10 of 145405 results

Filters:Package: pkg:bitnami/mlflow
Page 1 of 14541
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses