Skip to main content

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Package: pkg:bitnami/pillow

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

CVE-2026-91004 is a SQL injection vulnerability in SourceCodester Online Faculty Clearance System version 1.0. The issue exists in the /delete_faculty1.php file where manipulation of the ID parameter allows remote attackers to perform SQL injection. The vulnerability has a medium severity with a CVSS score of 6.9. There is no information about an available patch or official fix. Exploit details have been publicly disclosed but there are no known exploits in the wild at this time.

Join the discussion

The WP Directory Kit WordPress plugin versions up to 1.5.7 contains an information exposure vulnerability. This flaw allows unauthenticated attackers to access draft and unapproved listings of other users via a public AJAX action, due to missing checks on listing status and ownership.

Join the discussion

The WP Directory Kit WordPress plugin versions up to 1.5.7 contains an information exposure vulnerability. This flaw allows users with Contributor-level roles to access non-public listing content, including password-protected and hidden fields of other users, due to missing authorization checks in one of its shortcodes.

Join the discussion

The WP Directory Kit WordPress plugin up to version 1.5.7 contains a SQL injection vulnerability. This occurs because some widget settings are not properly sanitized and escaped before being used in SQL queries. Authenticated users with Editor-level or higher privileges who have access to the page builder can exploit this flaw to perform SQL injection when the affected page is rendered.

Join the discussion

The Android application "ManabiPocket for Parents" by NTT DOCOMO BUSINESS, Inc. has an improper access control vulnerability in one of its components. This flaw allows a malicious application on the same device to exploit the affected component via an Intent and potentially access sensitive information. The vulnerability affects versions from 0 up to and including 1.2.3. The CVSS score is low, indicating limited impact and requiring user interaction for exploitation.

Join the discussion

CVE-2026-91003 is a critical stack-based buffer overflow vulnerability in the D-Link DI-8300 router firmware version 16.07. The flaw exists in the rzgl_asp function of the /rzgl.asp CGI service component, where improper handling of the redirct_url argument allows remote attackers to cause a buffer overflow. Exploit code has been published, enabling potential remote exploitation without user interaction.

Join the discussion

CVE-2026-81320 is a vulnerability in the hawtio-operator component of the Red Hat build of Apache Camel - HawtIO 4. When a custom Route TLS secret is configured and the operator runs at debug log level 1 or higher, the operator logs the entire Route object including the TLS private key in PEM format to standard output. These logs are typically forwarded to centralized logging systems accessible to users with pods/log access in the openshift-operators namespace. This exposure can allow attackers with log access to obtain private keys, potentially enabling impersonation or decryption of traffic. The vulnerability has a medium severity with a CVSS score of 5.5. Mitigation involves setting the operator log verbosity to 0 (default) to prevent logging sensitive key material and rotating any TLS secrets exposed if debug logging was previously enabled.

Join the discussion

CVE-2026-81303 is a medium severity vulnerability in the hawtio-operator component of the Red Hat build of Apache Camel - HawtIO 4. The operator improperly writes tenant-supplied hostnames into OpenShift Route specifications without validating authorization, allowing a namespace edit user to claim arbitrary externally-routable hostnames. This confused deputy flaw can enable subdomain takeover and, when combined with other issues, OAuth redirect hijacking. Mitigations include restricting creation/modification of Hawtio custom resources via RBAC and configuring route admission policies to reject unauthorized hostnames.

Join the discussion

CVE-2026-91002 is a medium severity vulnerability in stamparm maltrail up to version 3.0.1. It affects the _blacklist function in the core/httpd.py file, allowing remote attackers to bypass authentication. The issue was fixed in version 3.1 by requiring authenticated sessions or using the Blacklist_ALLOWLIST option.

Join the discussion

A vulnerability in the email parsing of Cisco AsyncOS Software for Cisco Secure Email Gateway could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileges on the underlying operating system. This vulnerability is due to insufficient validation in the email parsing logic. An attacker could exploit this vulnerability by sending a crafted email message that contains malicious SQL statements through an affected device. A successful exploit could allow the attacker to execute arbitrary SQL statements, leading to command execution with root privileges on the underlying operating system.

Join the discussion

Showing 1 to 10 of 131710 results

Filters:Package: pkg:bitnami/pillow
Page 1 of 13171
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses