Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
0 CVE-2026-102829 is a critical OS command injection vulnerability in the steveukx git-js package, specifically related to the argv-parser dependency prior to version 2.0.1. The flaw allows attacker-controlled environment variables to influence Git operations by causing Git to invoke an attacker-selected editor, potentially executing arbitrary commands with the privileges of the Node.js process. This occurs when the VISUAL environment variable is omitted from GitEnvKeys and not properly classified as unsafe, enabling exploitation during Git operations like commit amendment or interactive rebase. The issue is fixed in argv-parser version 2.0.1. Join the discussion | CVE Database V5 | 09/29/2026, 18:46:58 UTC Added: 09/29/2026, 19:07:33 UTC |
0 CVE-2026-102616 is a medium severity SQL injection vulnerability in risesoft-y9 WorkFlow-Engine versions 9.6.0 through 9.6.10. The flaw exists in the getByIdAndYear function of the CustomHistoricProcessServiceImpl.java file within the OAuth2 Resource Filter component. Manipulating the year or processInstanceId arguments can lead to SQL injection. The vulnerability allows remote exploitation and has two independent injectable points. The vendor has not responded to disclosure attempts, and no patch information is available. Join the discussion | CVE Database V5 | 09/29/2026, 18:45:09 UTC Added: 09/29/2026, 19:07:33 UTC |
0 CVE-2026-102828 is a critical OS command injection vulnerability in the steveukx git-js library, specifically in versions from 3.15.0 up to but not including 4.0.1. The issue arises because the default blockUnsafeOperationsPlugin does not treat trailer.<token>.cmd as unsafe, allowing attacker-controlled input via SimpleGitOptions.config or inline -c arguments to execute arbitrary shell commands with the Node.js process's OS permissions. This vulnerability is fixed in version 4.0.1. Join the discussion | CVE Database V5 | 09/29/2026, 18:43:19 UTC Added: 09/29/2026, 18:51:53 UTC |
0 CVE-2026-102827 is a command injection vulnerability in the steveukx git-js library prior to version 4.0.0. The issue arises because the default blockUnsafeOperationsPlugin does not properly handle unambiguous long-option abbreviations in Git commands, allowing attacker-controlled push arguments to bypass security checks. This can lead to arbitrary command execution via git push operations. The vulnerability is fixed in version 4.0.0. Join the discussion | CVE Database V5 | 09/29/2026, 18:39:57 UTC Added: 09/29/2026, 18:51:53 UTC |
0 Vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to Remote Code Execution or Denial of Service Join the discussion | CVE Database V5 | 09/29/2026, 18:37:12 UTC Added: 09/27/2026, 16:33:34 UTC |
0 CVE-2026-102826 is a command injection vulnerability in the simple-git interface (git-js) for Node.js applications. Versions prior to 4.0.0 do not fully block unsafe operations when using custom arguments in git.clone(), allowing attacker-controlled configuration files to be loaded. This can lead to execution of arbitrary commands with the privileges of the Node.js process. The issue is fixed in version 4.0.0. Join the discussion | CVE Database V5 | 09/29/2026, 18:37:10 UTC Added: 09/29/2026, 18:51:53 UTC |
0 CVE-2026-102825 is a vulnerability in the Eugeny russh Rust SSH client and server library that allows an unauthenticated remote client to bypass the configured maximum authentication attempts limit. Prior to version 0.62.6, the authentication attempt counter increments but is never compared against the maximum allowed attempts, enabling excessive authentication requests on a single connection. This increases the risk of online guessing attacks and adds unnecessary backend authentication workload. The issue is fixed in version 0.62.6. Join the discussion | CVE Database V5 | 09/29/2026, 18:31:32 UTC Added: 09/29/2026, 18:51:53 UTC |
0 CVE-2026-102824 is a vulnerability in the Eugeny russh Rust SSH client and server library prior to version 0.63.0. The issue involves the hybrid ML-KEM 768 and X25519 key exchange implementation accepting an all-zero 32-byte peer X25519 public key, which causes the X25519 contribution to the combined shared secret to be zero. This allows a malicious SSH peer to force the shared secret to depend solely on ML-KEM, undermining the hybrid exchange's fallback protection. The vulnerability is fixed in version 0.63.0. Join the discussion | CVE Database V5 | 09/29/2026, 18:27:41 UTC Added: 09/29/2026, 18:37:06 UTC |
CVE-2026-102823 is an improper input validation vulnerability in the Eugeny russh Rust SSH client and server library. Versions prior to 0.63.1 improperly forward certain SSH channel lifecycle events to client handlers without verifying that the channel identifiers belong to channels the client opened and established. This can allow a malicious SSH server to send events for channels that are unopened or released, potentially causing application panics or corrupting command completion and exit-code tracking. The issue is fixed in version 0.63.1. Join the discussion | CVE Database V5 | 09/29/2026, 18:25:58 UTC Added: 09/29/2026, 18:37:06 UTC |
CVE-2026-102822 is a low-severity vulnerability in the Russh Rust SSH client and server library prior to version 0.63.1. It involves improper validation of array indices when a connection is configured to permit mac=none but negotiates a MAC-requiring cipher. This can cause a panic and termination of the connection task due to an out-of-bounds slice operation. The issue is fixed in version 0.63.1. Join the discussion | CVE Database V5 | 09/29/2026, 18:23:28 UTC Added: 09/29/2026, 18:37:06 UTC |
Showing 1 to 10 of 140579 results