Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

CVE-2026-87737: CWE-208 Observable Timing Discrepancy in OCaml mirage-crypto-ecCVE-2026-87737
0

An issue was discovered in the mirage-crypto-ec package before 2.4.0 for OCaml. There is a timing side channel for NIST elliptic-curve scalar multiplication: the time required for a lookup can depend on a secret.

Join the discussion
CVE-2026-87736: CWE-125 Out-of-bounds Read in OCaml mirage-crypto-ecCVE-2026-87736
0

An issue was discovered in the mirage-crypto-ec package before 2.3.0 for OCaml. There is an EC public key out-of-bounds read for compressed points.

Join the discussion
CVE-2026-87735: CWE-1284 Improper Validation of Specified Quantity in Input in OCaml mirage-crypto-pkCVE-2026-87735
0

An issue was discovered in the mirage-crypto-pk package before 2.3.0 for OCaml. There is an undocumented exception for a small message during RSA decryption or encryption.

Join the discussion
CVE-2026-87734: CWE-923 Improper Restriction of Communication Channel to Intended Endpoints in OCaml utcpCVE-2026-87734
0

An issue was discovered in the utcp package before 0.0.6 for OCaml. Out-of-order segment reassembly allows remote denial of service.

Join the discussion
CVE-2026-87733: CWE-295 Improper Certificate Validation in OCaml mirage-crypto-ecCVE-2026-87733
0

An issue was discovered in the mirage-crypto-ec function before 2.2.0 for OCaml. The ECDSA functions {P256,P384,P521}.Dsa.pub_of_octets accept 0x00, the encoding of the point at infinity, as a public key. With that public key, signatures can be forged without a private key.

Join the discussion
CVE-2026-87732: CWE-347 Improper Verification of Cryptographic Signature in OCaml mirage-cryptoCVE-2026-87732
0

An issue was discovered in the mirage-crypto package before 2.2.0 for OCaml. The AES.GCM.authenticate_decrypt_into and Chacha20.authenticate_decrypt_into functions write the decrypted plaintext into a caller-provided buffer and only then compares the tag. On a forged tag, the functions returns false, but the destination buffer already holds the full plaintext.

Join the discussion
CVE-2026-19945: CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in themeum WP CrowdfundingCVE-2026-19945
0

The WP Crowdfunding plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'first_name' parameter in all versions up to, and including, 2.2.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. An administrator viewing any user's profile via the ?show_user_id= parameter will render the attacker's stored payload in the admin's browser session, enabling cross-privilege script execution.

Join the discussion
CVE-2026-11821: CWE-862 Missing Authorization in arraytics Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerceCVE-2026-11821
0

The Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.1.17. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to view, create, update, clone, and delete notification flow event automation workflows that should be restricted to administrators.

Join the discussion
CVE-2026-6485: CWE-489: Active Debug Code in Insyde Software InsydeH2OCVE-2026-6485
0

CVE-2026-6485 is a high-severity vulnerability in Insyde Software's InsydeH2O UEFI BIOS. It involves active debug code in the embedded UEFI Shell that could be exploited to bypass Secure Boot protections using shell commands or startup scripts. This vulnerability impacts system integrity, confidentiality, and availability. No specific affected versions or patches are currently confirmed.

Join the discussion
CVE-2026-49315: CWE-264 Permissions, Privileges, and Access Controls in Huawei HarmonyOSCVE-2026-49315
0

CVE-2026-49315 is a denial-of-service (DoS) vulnerability in the input device module of Huawei HarmonyOS. Exploitation of this flaw can impact system availability without affecting confidentiality or integrity. The vulnerability affects specific versions of HarmonyOS including 4.0.0, 4.2.0, 4.3.0, 4.3.1, and 4.3.3. No official patch or remediation guidance has been provided yet.

Join the discussion

Showing 1 to 10 of 19019 results

Filters:Package: pkg:bitnami/openbao
Page 1 of 1902
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses