Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
CVE-2026-86144: CWE-669 Incorrect Resource Transfer Between Spheres in xmlsoft libxml2CVE-2026-86144 0 In xinclude in libxml2 before 2.15.4, xmlXIncludeProcess and xmlXIncludeProcessTree do not propagate parseFlags. This has security relevance for, for example, the XML_PARSE_NONET flag, if (without it) a custom resource loader accesses the internet and triggers XML external entity injection, SSRF, or a denial of service (e.g., for an attacker-controlled internet resource that is intentionally slow). Join the discussion | CVE Database V5 | 09/05/2026, 04:34:43 UTC Added: 09/05/2026, 04:52:56 UTC |
CVE-2026-86143: CWE-192 Integer Coercion Error in xmlsoft libxml2CVE-2026-86143 0 In xmlIO in libxml2 before 2.15.4, an inconsistency in xmlOutputWriteCallback and xmlBufUse causes negative lengths to reach write callbacks, aka a lack of a check for integer overflow before calling writecallback. This has security relevance for many types of uses of that length value within a callback. Join the discussion | CVE Database V5 | 09/05/2026, 04:31:21 UTC Added: 09/05/2026, 04:37:54 UTC |
CVE-2026-86142: CWE-122 Heap-based Buffer Overflow in xmlsoft libxml2CVE-2026-86142 0 In libxml2 before 2.15.4, there is a heap-based buffer overflow in xmlXPtrEvalXPtrPart because of xmlXPtrEval xpointer length saturation. Join the discussion | CVE Database V5 | 09/05/2026, 04:29:33 UTC Added: 09/05/2026, 04:37:54 UTC |
CVE-2026-86141: CWE-252 Unchecked Return Value in xmlsoft libxml2CVE-2026-86141 0 xmlregexp in libxml2 before 2.15.4 has a NULL pointer dereference in xmlRegNewParserCtxt after a strdup failure, i.e., it does not calculate a string length after NULL checking. Join the discussion | CVE Database V5 | 09/05/2026, 04:27:59 UTC Added: 09/05/2026, 04:37:54 UTC |
CVE-2026-86140: CWE-121 Stack-based Buffer Overflow in xmlsoft libxml2CVE-2026-86140 0 In libxml2 before 2.15.4, xmlSnprintfElements in valid.c has a strcat stack-based buffer overflow. Join the discussion | CVE Database V5 | 09/05/2026, 04:26:13 UTC Added: 09/05/2026, 04:37:54 UTC |
CVE-2026-86139: CWE-190 Integer Overflow or Wraparound in xmlsoft libxml2CVE-2026-86139 0 In libxml2 before 2.15.4, xmlURIEscapeStr in uri.c has an integer overflow. Join the discussion | CVE Database V5 | 09/05/2026, 04:23:14 UTC Added: 09/05/2026, 04:37:54 UTC |
AI model Cyberkimi claims it turned a 3-day-old V8 patch into a live Chrome exploit in under 24 hours 0 AI model Cyberkimi claims it turned a 3-day-old V8 patch into a live Chrome exploit in under 24 hours Source: https://x.com/lordx64/status/2096052694326940018?s=20 Join the discussion | Reddit Cybersecurity | 09/05/2026, 02:45:39 UTC Added: 09/05/2026, 02:52:09 UTC |
ThreatFox MISP Feed | 09/04/2026, 00:00:00 UTC Added: 09/05/2026, 00:37:01 UTC | |
CVE-2026-86100: CWE-918 Server-Side Request Forgery (SSRF) in owen2345 CamaleonCMSCVE-2026-86100 0 Camaleon CMS versions 2.7.5 through 2.9.1 fail to validate redirect targets when fetching remote files in the Upload from URL media feature. Authenticated attackers can supply URLs that pass initial validation but redirect to internal network addresses, allowing server-side request forgery to internal services. Join the discussion | CVE Database V5 | 09/04/2026, 23:16:23 UTC Added: 09/04/2026, 23:22:43 UTC |
CVE-2026-86098: Out-of-bounds Write in ntop nDPICVE-2026-86098 0 ntop nDPI versions before 6.0 contain a heap buffer overflow vulnerability in the ndpi_json_string_escape function that writes beyond caller-supplied buffer boundaries. Attackers can trigger the overflow by supplying crafted network packet data including TLS SNI, HTTP headers, or DNS names that reach the vulnerable function, causing heap corruption. Join the discussion | CVE Database V5 | 09/04/2026, 22:38:48 UTC Added: 09/04/2026, 22:52:51 UTC |
Showing 1 to 10 of 17716 results