Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

CVE-2026-87737: CWE-208 Observable Timing Discrepancy in OCaml mirage-crypto-ecCVE-2026-87737
0

CVE-2026-87737 is a timing side-channel vulnerability in the mirage-crypto-ec package for OCaml, affecting versions before 2.4.0. The issue arises from the time required for a lookup during NIST elliptic-curve scalar multiplication depending on a secret value, potentially leaking sensitive information. The vulnerability has a medium severity with a CVSS score of 5.9.

Join the discussion
CVE-2026-87736: CWE-125 Out-of-bounds Read in OCaml mirage-crypto-ecCVE-2026-87736
0

CVE-2026-87736 is a medium severity vulnerability in the mirage-crypto-ec package for OCaml, affecting versions before 2.3.0. It involves an out-of-bounds read when processing compressed elliptic curve public keys. This flaw does not impact confidentiality or integrity but can cause availability issues such as application crashes.

Join the discussion
CVE-2026-87735: CWE-1284 Improper Validation of Specified Quantity in Input in OCaml mirage-crypto-pkCVE-2026-87735
0

CVE-2026-87735 is a medium severity vulnerability in the mirage-crypto-pk package for OCaml versions before 2.3.0. It involves an undocumented exception triggered by a small message during RSA encryption or decryption. This improper validation of the specified quantity in input may cause availability issues but does not impact confidentiality or integrity.

Join the discussion
CVE-2026-87734: CWE-923 Improper Restriction of Communication Channel to Intended Endpoints in OCaml utcpCVE-2026-87734
0

CVE-2026-87734 is a high-severity vulnerability in the OCaml utcp package before version 0.0.6. It involves improper restriction of communication channels, specifically out-of-order segment reassembly, which can be exploited remotely to cause a denial of service (DoS). No patch or official remediation has been confirmed yet. There are no known exploits in the wild at this time.

Join the discussion
CVE-2026-87733: CWE-295 Improper Certificate Validation in OCaml mirage-crypto-ecCVE-2026-87733
0

CVE-2026-87733 is a vulnerability in the mirage-crypto-ec library for OCaml before version 2.2.0. The issue involves improper certificate validation where the ECDSA functions for P256, P384, and P521 curves accept the encoding of the point at infinity (0x00) as a valid public key. This flaw allows an attacker to forge signatures without possessing the private key. The vulnerability has a medium severity with a CVSS score of 6.2 and does not impact confidentiality or availability but compromises integrity. No official patch or remediation guidance is currently available, and no known exploits are reported in the wild.

Join the discussion
CVE-2026-87732: CWE-347 Improper Verification of Cryptographic Signature in OCaml mirage-cryptoCVE-2026-87732
0

CVE-2026-87732 is a vulnerability in the mirage-crypto package for OCaml versions before 2.2.0. The AES.GCM.authenticate_decrypt_into and Chacha20.authenticate_decrypt_into functions decrypt data into a provided buffer before verifying the cryptographic tag. If the tag is forged, the functions return false but the plaintext remains in the buffer, potentially exposing sensitive data.

Join the discussion
CVE-2026-19945: CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in themeum WP CrowdfundingCVE-2026-19945
0

WP Crowdfunding plugin for WordPress versions up to and including 2.2.1 is vulnerable to a stored cross-site scripting (XSS) flaw via the 'first_name' parameter. Authenticated users with subscriber-level access or higher can inject malicious scripts that execute when an administrator views a user's profile using the ?show_user_id= parameter. This vulnerability arises from insufficient input sanitization and output escaping.

Join the discussion
CVE-2026-11821: CWE-862 Missing Authorization in arraytics Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerceCVE-2026-11821
0

CVE-2026-11821 is a medium severity authorization bypass vulnerability in the Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce WordPress plugin. It affects all versions up to and including 4.1.17. The flaw allows authenticated users with subscriber-level access or higher to perform administrative actions on notification flow event automation workflows, including viewing, creating, updating, cloning, and deleting them. This occurs because the plugin does not properly verify user authorization for these actions.

Join the discussion
CVE-2026-6485: CWE-489: Active Debug Code in Insyde Software InsydeH2OCVE-2026-6485
0

CVE-2026-6485 is a high-severity vulnerability in Insyde Software's InsydeH2O UEFI BIOS. It involves active debug code in the embedded UEFI Shell that could be exploited to bypass Secure Boot protections using shell commands or startup scripts. This vulnerability impacts system integrity, confidentiality, and availability. No specific affected versions or patches are currently confirmed.

Join the discussion
CVE-2026-49315: CWE-264 Permissions, Privileges, and Access Controls in Huawei HarmonyOSCVE-2026-49315
0

CVE-2026-49315 is a denial-of-service (DoS) vulnerability in the input device module of Huawei HarmonyOS. Exploitation of this flaw can impact system availability without affecting confidentiality or integrity. The vulnerability affects specific versions of HarmonyOS including 4.0.0, 4.2.0, 4.3.0, 4.3.1, and 4.3.3. No official patch or remediation guidance has been provided yet.

Join the discussion

Showing 1 to 10 of 19018 results

Filters:Package: pkg:bitnami/valkey
Page 1 of 1902
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses