Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
CVE-2026-87737: CWE-208 Observable Timing Discrepancy in OCaml mirage-crypto-ecCVE-2026-87737 0 CVE-2026-87737 is a timing side-channel vulnerability in the mirage-crypto-ec package for OCaml, affecting versions before 2.4.0. The issue arises from the time required for a lookup during NIST elliptic-curve scalar multiplication depending on a secret value, potentially leaking sensitive information. The vulnerability has a medium severity with a CVSS score of 5.9. Join the discussion | CVE Database V5 | 09/09/2026, 04:21:37 UTC Added: 09/09/2026, 04:38:29 UTC |
CVE-2026-87736: CWE-125 Out-of-bounds Read in OCaml mirage-crypto-ecCVE-2026-87736 0 CVE-2026-87736 is a medium severity vulnerability in the mirage-crypto-ec package for OCaml, affecting versions before 2.3.0. It involves an out-of-bounds read when processing compressed elliptic curve public keys. This flaw does not impact confidentiality or integrity but can cause availability issues such as application crashes. Join the discussion | CVE Database V5 | 09/09/2026, 04:19:00 UTC Added: 09/09/2026, 04:38:29 UTC |
CVE-2026-87735: CWE-1284 Improper Validation of Specified Quantity in Input in OCaml mirage-crypto-pkCVE-2026-87735 0 CVE-2026-87735 is a medium severity vulnerability in the mirage-crypto-pk package for OCaml versions before 2.3.0. It involves an undocumented exception triggered by a small message during RSA encryption or decryption. This improper validation of the specified quantity in input may cause availability issues but does not impact confidentiality or integrity. Join the discussion | CVE Database V5 | 09/09/2026, 04:16:24 UTC Added: 09/09/2026, 04:38:29 UTC |
CVE-2026-87734: CWE-923 Improper Restriction of Communication Channel to Intended Endpoints in OCaml utcpCVE-2026-87734 0 CVE-2026-87734 is a high-severity vulnerability in the OCaml utcp package before version 0.0.6. It involves improper restriction of communication channels, specifically out-of-order segment reassembly, which can be exploited remotely to cause a denial of service (DoS). No patch or official remediation has been confirmed yet. There are no known exploits in the wild at this time. Join the discussion | CVE Database V5 | 09/09/2026, 04:13:55 UTC Added: 09/09/2026, 04:38:29 UTC |
CVE-2026-87733: CWE-295 Improper Certificate Validation in OCaml mirage-crypto-ecCVE-2026-87733 0 CVE-2026-87733 is a vulnerability in the mirage-crypto-ec library for OCaml before version 2.2.0. The issue involves improper certificate validation where the ECDSA functions for P256, P384, and P521 curves accept the encoding of the point at infinity (0x00) as a valid public key. This flaw allows an attacker to forge signatures without possessing the private key. The vulnerability has a medium severity with a CVSS score of 6.2 and does not impact confidentiality or availability but compromises integrity. No official patch or remediation guidance is currently available, and no known exploits are reported in the wild. Join the discussion | CVE Database V5 | 09/09/2026, 04:08:54 UTC Added: 09/09/2026, 04:38:29 UTC |
CVE-2026-87732: CWE-347 Improper Verification of Cryptographic Signature in OCaml mirage-cryptoCVE-2026-87732 0 CVE-2026-87732 is a vulnerability in the mirage-crypto package for OCaml versions before 2.2.0. The AES.GCM.authenticate_decrypt_into and Chacha20.authenticate_decrypt_into functions decrypt data into a provided buffer before verifying the cryptographic tag. If the tag is forged, the functions return false but the plaintext remains in the buffer, potentially exposing sensitive data. Join the discussion | CVE Database V5 | 09/09/2026, 04:03:53 UTC Added: 09/09/2026, 04:38:29 UTC |
CVE-2026-19945: CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in themeum WP CrowdfundingCVE-2026-19945 0 WP Crowdfunding plugin for WordPress versions up to and including 2.2.1 is vulnerable to a stored cross-site scripting (XSS) flaw via the 'first_name' parameter. Authenticated users with subscriber-level access or higher can inject malicious scripts that execute when an administrator views a user's profile using the ?show_user_id= parameter. This vulnerability arises from insufficient input sanitization and output escaping. Join the discussion | CVE Database V5 | 09/09/2026, 04:28:34 UTC Added: 09/09/2026, 04:38:29 UTC |
CVE-2026-11821: CWE-862 Missing Authorization in arraytics Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerceCVE-2026-11821 0 CVE-2026-11821 is a medium severity authorization bypass vulnerability in the Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce WordPress plugin. It affects all versions up to and including 4.1.17. The flaw allows authenticated users with subscriber-level access or higher to perform administrative actions on notification flow event automation workflows, including viewing, creating, updating, cloning, and deleting them. This occurs because the plugin does not properly verify user authorization for these actions. Join the discussion | CVE Database V5 | 09/09/2026, 04:28:34 UTC Added: 09/09/2026, 04:38:29 UTC |
CVE-2026-6485: CWE-489: Active Debug Code in Insyde Software InsydeH2OCVE-2026-6485 0 CVE-2026-6485 is a high-severity vulnerability in Insyde Software's InsydeH2O UEFI BIOS. It involves active debug code in the embedded UEFI Shell that could be exploited to bypass Secure Boot protections using shell commands or startup scripts. This vulnerability impacts system integrity, confidentiality, and availability. No specific affected versions or patches are currently confirmed. Join the discussion | CVE Database V5 | 09/09/2026, 03:54:01 UTC Added: 09/09/2026, 04:07:58 UTC |
CVE-2026-49315: CWE-264 Permissions, Privileges, and Access Controls in Huawei HarmonyOSCVE-2026-49315 0 CVE-2026-49315 is a denial-of-service (DoS) vulnerability in the input device module of Huawei HarmonyOS. Exploitation of this flaw can impact system availability without affecting confidentiality or integrity. The vulnerability affects specific versions of HarmonyOS including 4.0.0, 4.2.0, 4.3.0, 4.3.1, and 4.3.3. No official patch or remediation guidance has been provided yet. Join the discussion | CVE Database V5 | 09/09/2026, 03:52:06 UTC Added: 09/09/2026, 04:07:58 UTC |
Showing 1 to 10 of 19018 results