Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
0 CVE-2026-17544 is a high-severity vulnerability in the PHP programming language affecting versions 8.4.0 through 8.4.23 and 8.5.0 through 8.5.8. It involves an out-of-bounds write triggered by attacker-controlled inputs to the bccomp() function, which can cause stack and heap corruption. This vulnerability could potentially lead to serious memory corruption issues. No official patch or remediation level has been confirmed yet. Join the discussion | CVE Database V5 | 08/17/2026, 05:53:36 UTC Added: 07/30/2026, 11:37:38 UTC |
CVE-2026-7260 is a stack-based buffer overflow vulnerability in PHP caused by circular symbolic links in phar archives. This flaw can trigger unbounded recursion, exhausting the C stack and crashing the PHP process. It affects PHP versions prior to 8.2.33, 8.3.33, 8.4.24, and 8.5.9. The vulnerability has a medium severity rating with a CVSS score of 5.4. No official patch or remediation level is currently confirmed in the provided data. Join the discussion | CVE Database V5 | 07/30/2026, 12:19:00 UTC Added: 07/30/2026, 11:37:38 UTC |
0 CVE-2026-17543 is a high-severity SQL injection vulnerability in PHP caused by improper escaping of backslashes in attacker-supplied parameters. It affects multiple PHP versions prior to 8.2.33, 8.3.33, 8.4.24, and 8.5.9. This flaw allows attackers to perform SQL injection attacks due to improper neutralization of special elements in SQL commands. No official patch or remediation level is currently confirmed. Join the discussion | CVE Database V5 | 07/30/2026, 11:22:04 UTC Added: 07/30/2026, 11:37:38 UTC |
In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, when a SOAP server has a typemap configured, the decoding process contains a mistake which checks the wrong variable in case of missing value element. This leads to dereferences a NULL pointer, causing a segmentation fault. This allows a remote unauthenticated attacker to crash the PHP SOAP server process, resulting in denial of service. Join the discussion | CVE Database V5 | 05/12/2026, 08:56:08 UTC Added: 05/10/2026, 04:36:24 UTC |
In PHP versions:8.1.* before 8.1.33, 8.2.* before 8.2.29, 8.3.* before 8.3.23, 8.4.* before 8.4.10 some functions like fsockopen() lack validation that the hostname supplied does not contain null characters. This may lead to other functions like parse_url() treat the hostname in different way, thus opening way to security problems if the user code implements access checks before access using such functions. Join the discussion | CVE Database V5 | 07/13/2025, 22:18:36 UTC Added: 07/13/2025, 22:31:03 UTC |
0 In PHP versions 8.1.* before 8.1.30, 8.2.* before 8.2.24, 8.3.* before 8.3.12, when using PHP-FPM SAPI and it is configured to catch workers output through catch_workers_output = yes, it may be possible to pollute the final log or remove up to 4 characters from the log messages by manipulating log message content. Additionally, if PHP-FPM is configured to use syslog output, it may be possible to further remove log data using the same vulnerability. Join the discussion | CVE Database V5 | 10/10/2024, 07:13:42 UTC Added: 11/03/2025, 22:53:13 UTC |
In PHP versions 8.1.* before 8.1.28, 8.2.* before 8.2.18, 8.3.* before 8.3.5, when using proc_open() command with array syntax, due to insufficient escaping, if the arguments of the executed command are controlled by a malicious user, the user can supply arguments that would execute arbitrary commands in Windows shell. Join the discussion | CVE Database V5 | 05/14/2024, 07:29:52 UTC Added: 11/04/2025, 17:44:01 UTC |
Due to an incomplete fix to CVE-2022-31629 https://github.com/advisories/GHSA-c43m-486j-j32p , network and same-site attackers can set a standard insecure cookie in the victim's browser which is treated as a __Host- or __Secure- cookie by PHP applications. Join the discussion | CVE Database V5 | 04/29/2024, 03:34:16 UTC Added: 11/04/2025, 17:44:09 UTC |
Showing 1 to 8 of 8 results