Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
0 CVE-2026-44898 is a cross-site scripting (XSS) vulnerability in the render_toc_ul() function of the Mistune TOC component used by recon-ng. The vulnerability arises because heading IDs and text are inserted into HTML anchor tags without proper escaping. When heading IDs are derived from user-supplied text, an attacker can inject arbitrary HTML and script code into the table of contents, leading to XSS. This affects recon-ng versions >=5.1.1_1 and <5.1.2_4. A patch is available to fix this issue. Join the discussion | GCVE Database | 08/13/2026, 17:32:25 UTC Added: 10/10/2026, 21:27:10 UTC |
A CSS injection vulnerability exists in the Image directive plugin of recon-ng due to improper validation of the :width: and :height: options. The regex used only anchors at the start of the string, allowing values that begin with digits but contain arbitrary CSS to pass validation. This leads to unescaped CSS being injected into the style attribute of rendered images, enabling attackers to create full-page overlays that can be used for phishing or UI redressing attacks. The vulnerability affects recon-ng versions >=5.1.1_1 and <5.1.2_4. A patch is available to address this issue. Join the discussion | GCVE Database | 08/13/2026, 17:32:25 UTC Added: 10/10/2026, 21:27:10 UTC |
The Adr viewer's Mistune math plugin in recon-ng versions >=1.3.0 <1.4.0_5 and >=5.1.1_1 <5.1.2_4 contains a cross-site scripting (XSS) vulnerability. This occurs because the plugin improperly escapes user input within math delimiters, allowing malicious HTML or script code to be injected and executed in the browser. The vulnerability exists even when the parser is configured with escape=True. A patch is available to address this issue. Join the discussion | GCVE Database | 08/13/2026, 17:32:25 UTC Added: 09/18/2026, 01:04:24 UTC |
A cross-site scripting (XSS) vulnerability exists in the adr-viewer component of Mistune's HTMLRenderer used by recon-ng. The vulnerability occurs when the heading ID attribute is inserted into HTML without proper escaping, allowing an attacker controlling heading text to inject arbitrary HTML attributes including event handlers. This can lead to execution of malicious JavaScript. The default safe behavior uses auto-generated IDs, but the issue arises when a custom heading_id callback returns raw heading text. A patch is available to fix this issue. Join the discussion | GCVE Database | 08/13/2026, 17:32:25 UTC Added: 09/18/2026, 01:04:24 UTC |
CVE-2024-49766 is a vulnerability affecting Mapproxy on Windows systems running Python versions earlier than 3.11. It stems from Werkzeug's safe_join() function incorrectly handling UNC paths as absolute due to reliance on os.path.isabs() in these Python versions. This flaw can lead to unsafe path joins and potentially unintended data access. Systems using Python 3.11 or later, or non-Windows platforms, are not affected. A patch is available to remediate this issue. Join the discussion | GCVE Database | 08/13/2026, 17:32:25 UTC Added: 09/18/2026, 01:03:55 UTC |
0 Multiple vulnerabilities in the python-mistune library used by recon-ng can lead to denial of service and code injection attacks. These include ReDoS caused by crafted Markdown input and cross-site scripting (XSS) and CSS injection due to improper escaping and sanitization. The issues affect recon-ng versions from 5.1.2_1 up to but not including 5.1.2_4. A patch is available to address these vulnerabilities. Join the discussion | GCVE Database | 08/13/2026, 17:32:25 UTC Added: 09/17/2026, 01:59:29 UTC |
0 A vulnerability in recon-ng's use of Flask sessions causes the 'Vary: Cookie' header to be omitted in some cases when the session is accessed using certain methods such as the Python 'in' operator. This omission can lead to caching proxies improperly caching user-specific responses if certain conditions are met, potentially exposing sensitive session data. The risk depends on the application's caching setup and how it accesses the session object. Join the discussion | GCVE Database | 08/13/2026, 17:32:25 UTC Added: 09/17/2026, 01:59:27 UTC |
0 Mistune, a Markdown parsing library used in recon-ng, is vulnerable to a denial-of-service (DoS) attack due to quadratic-time parsing behavior in the parse_link_text function. This vulnerability causes excessive CPU consumption when processing Markdown inputs containing many consecutive '[' characters. The issue arises from inefficient looping and regex scanning that results in O(n²) complexity. An attacker can exploit this with a small payload to cause significant CPU exhaustion, impacting applications that parse user-supplied Markdown. A fix is available to optimize the parsing loop to avoid this superlinear behavior. Join the discussion | GCVE Database | 08/13/2026, 17:32:25 UTC Added: 09/17/2026, 01:59:13 UTC |
0 Recon-ng contains a cross-site scripting (XSS) vulnerability in the Mistune library's Figure directive. The vulnerability arises because the figclass and figwidth options are concatenated directly into HTML attributes without proper escaping, enabling attribute injection and XSS even when HTMLRenderer escape is enabled. Other attributes like src, alt, and style are properly escaped. This affects certain versions of recon-ng prior to patched releases. Join the discussion | GCVE Database | 08/13/2026, 17:32:25 UTC Added: 09/17/2026, 01:59:08 UTC |
Recon-ng's Adr viewer uses the mistune markdown renderer with strikethrough, mark, and insert plugins that have a denial of service vulnerability (CVE-2026-59922). The vulnerability is due to quadratic-time parsing when processing long runs of repeated markers such as `~~x~~`, `==x==`, or `^^x^^`. This causes excessive CPU usage from crafted inputs. A patch is available to fix this inefficiency. Join the discussion | GCVE Database | 08/13/2026, 17:32:25 UTC Added: 07/16/2026, 10:37:08 UTC |
Showing 1 to 10 of 20 results