Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
CVE-2026-82689: OS Command Injection in D-Link DNS-320LCVE-2026-82689 0 A vulnerability was detected in D-Link DNS-320L, DNS-327L, DNS-340L and DNS-345 up to 20260717. Affected is an unknown function of the file /cgi-bin/isomount_mgr.cgi of the component ISO Image Handler. The manipulation of the argument upIsoRootPath results in os command injection. The attack can be executed remotely. The exploit is now public and may be used. Join the discussion | CVE Database V5 | 08/31/2026, 11:15:09 UTC Added: 08/31/2026, 11:22:54 UTC |
CVE-2026-82881: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in apconw Aix-DBCVE-2026-82881 0 Aix-DB through 1.2.4 renders markdown with raw HTML enabled into v-html bindings without sanitization, allowing stored cross-site scripting attacks. Attackers can inject malicious HTML and JavaScript through markdown content in chat responses, skill descriptions, or knowledge messages that execute in users' browsers when viewed. Join the discussion | CVE Database V5 | 08/31/2026, 10:51:06 UTC Added: 08/31/2026, 11:07:40 UTC |
CVE-2026-82880: Improper Restriction of XML External Entity Reference in yacy yacy_search_serverCVE-2026-82880 0 YaCy Search Server through 1.941 contains an XML external entity injection vulnerability in SVG, FreeMind, and OpenSearch parsers that fail to disable external entity resolution. Attackers can publish malicious documents with DOCTYPE declarations containing SYSTEM entities pointing to local files, causing the crawler to exfiltrate file contents into the searchable index. Join the discussion | CVE Database V5 | 08/31/2026, 10:51:05 UTC Added: 08/31/2026, 11:07:40 UTC |
CVE-2026-82877: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in ILIAS-eLearning e.V. ILIASCVE-2026-82877 0 ILIAS versions before 9.22, 10.0 through 10.9, and 11.0 through 11.2 contain an arbitrary file read vulnerability in the SOAP addFile method that allows authenticated users to read server files by supplying crafted XML with COPY-mode imports. Attackers can construct absolute file paths through an unsandboxed import directory and retrieve sensitive files including configuration files containing database credentials and setup passwords. Join the discussion | CVE Database V5 | 08/31/2026, 10:51:03 UTC Added: 08/31/2026, 11:07:40 UTC |
CVE-2026-82876: Improper Verification of Cryptographic Signature in Phison Electronics Corporation PS3111-S11 Controller FirmwareCVE-2026-82876 0 Phison PS3111-S11 controller firmware verifies RSA signatures using a public modulus embedded within the firmware image itself rather than anchored in immutable storage. Attackers can generate arbitrary RSA key pairs, sign modified firmware with the private key, embed the matching modulus in the signature segment, and the controller accepts the tampered firmware as valid. Join the discussion | CVE Database V5 | 08/31/2026, 10:51:03 UTC Added: 08/31/2026, 11:07:40 UTC |
CVE-2026-82688: OS Command Injection in D-Link DNS-340LCVE-2026-82688 0 A security vulnerability has been detected in D-Link DNS-340L and DNS-345 1.01B04/1.03B06/1.04.B02/1.05b04. This impacts an unknown function of the file /cgi-bin/virtual_vol.cgi of the component Virtual Volume Handler. The manipulation of the argument f_sharename/f_target/f_name leads to os command injection. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used. Join the discussion | CVE Database V5 | 08/31/2026, 11:00:10 UTC Added: 08/31/2026, 11:07:40 UTC |
CVE-2026-56718: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in AJCloud AJY IPC FirmwareCVE-2026-56718 0 AJCloud AJY IPC firmware prior to version 01.10715.11.37 contains a path traversal vulnerability in the jdbhttpd web service that allows unauthenticated remote attackers to read arbitrary files with root privileges by supplying path traversal sequences in the HTTP request URI. Attackers can send crafted HTTP requests to port 80 without authentication to access sensitive files including cleartext RTSP credentials, Wi-Fi SSID and pre-shared key, device serial number, and cloud binding parameters. Join the discussion | CVE Database V5 | 08/30/2026, 20:13:01 UTC Added: 08/31/2026, 11:04:41 UTC |
CVE-2026-82619: Use After Free in Systerel S2OPCCVE-2026-82619 0 A vulnerability was identified in Systerel S2OPC up to 1.7.3. The impacted element is the function monitored_item_event_filter_treatment_bs__init_event_filter_ctx_and_result of the file src/ClientServer/services/bgenc/subscription_mgr.c. Such manipulation of the argument EventFilter leads to use after free. The attack may be performed from remote. The exploit is publicly available and might be used. The name of the patch is a4cee16a851b971be447a6ed531173702c722b99. It is best practice to apply a patch to resolve this issue. Join the discussion | CVE Database V5 | 08/31/2026, 05:15:10 UTC Added: 08/31/2026, 11:04:41 UTC |
CVE-2026-82680: Out-of-bounds Write in D-Link DSM-G600CVE-2026-82680 0 A weakness has been identified in D-Link DSM-G600 1.01. This affects an unknown function of the file /load_file.cgi of the component Multipart Handler. Executing a manipulation can lead to out-of-bounds write. The attack may be launched remotely. The exploit has been made available to the public and could be used for attacks. Join the discussion | CVE Database V5 | 08/31/2026, 10:45:09 UTC Added: 08/31/2026, 10:52:41 UTC |
CVE-2026-82678: OS Command Injection in diem-project diemCVE-2026-82678 0 A vulnerability was identified in diem-project diem up to 5.1.3. The affected element is the function executeCommand of the file dmAdminPlugin/modules/dmConsole/actions/actions.class.php of the component Administrative Console. Such manipulation of the argument dm_command leads to os command injection. The attack can be launched remotely. The exploit is publicly available and might be used. The project was informed of the problem early through an issue report but has not responded yet. Join the discussion | CVE Database V5 | 08/31/2026, 10:15:09 UTC Added: 08/31/2026, 10:37:56 UTC |
Showing 1 to 10 of 16682 results