Skip to main content

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Package: pkg:generic/binutils

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

CVE-2026-102293 is a medium severity vulnerability in realjerrytang tacomall version 1.0.0. It involves improper authorization in the OrgStaffServiceImpl.add function within the api-admin backend component. The vulnerability arises from manipulation of the isAdmin/jobId argument, allowing unauthorized actions. Remote exploitation is possible, and public exploit code exists.

Join the discussion

CVE-2026-102292 is a cross-site scripting (XSS) vulnerability in the coolbeans1212 MateisHomePage-Website affecting the users.php file via manipulation of the Search argument. The vulnerability allows remote attackers to inject malicious scripts. The product uses continuous delivery with rolling releases, so no specific affected or fixed versions are available. A patch identified by commit 6406308df9771d2fd477b56dafe4878dd846df6e is recommended to remediate the issue.

Join the discussion

Multiple vulnerabilities have been identified in Pgpool-II, a software provided by the Pgpool Global Development Group. Specific details about the nature of these vulnerabilities, affected versions, or exploitation methods have not been disclosed.

MediumVulnerability
Join the discussion

CVE-2026-102290 is a cross-site scripting (XSS) vulnerability in CodeCanyon Rocket LMS versions 2.0, 2.1, and 2.2. The flaw exists in the Student Profile Image Upload component and can be exploited remotely by an attacker to execute malicious scripts. The vulnerability has been publicly disclosed, but the vendor has not responded or provided a patch. The CVSS 4.0 base score is 5.1, indicating a medium severity risk.

Join the discussion

CVE-2026-102264 is a cross-site scripting (XSS) vulnerability in the mwasikz robo-cafe-rms product affecting the Edit Profile feature in the frontend/update-account.php file. Manipulating the Name, Address, or City parameters can lead to XSS. The vulnerability allows remote exploitation and public exploit code is available. The product uses a rolling release model, so specific affected versions are not provided. The vendor has not responded to the disclosure. The CVSS 4.0 score rates this as a medium severity issue.

Join the discussion

CVE-2026-102263 is a medium-severity vulnerability in the mwasikz robo-cafe-rms software, specifically involving an unrestricted file upload issue in the manage-food.php file. The vulnerability allows remote attackers to upload files without restriction. The product uses a rolling release model, so no specific affected or fixed versions are identified. The vendor was notified but did not respond, and the exploit has been publicly disclosed.

Join the discussion

CVE-2026-102261 is an authorization bypass vulnerability in owen2345 Camaleon CMS affecting versions 2.9.0, 2.9.1, and 2.9.2. The flaw exists in the Media Crop Handler component, specifically in the crop function of app/controllers/camaleon_cms/admin/media_controller.rb. The vulnerability allows remote attackers to bypass authorization by manipulating the saved_avatar argument. An exploit has been published. Upgrading to version 2.9.3 addresses this issue.

Join the discussion

shell-quote's `quote()` function emits a `{ comment }` token as `#` followed by its text, which comments out the rest of the shell line, including the opening quote of any later string token. A line terminator (\n, \r, U+2028, U+2029) in that later string therefore ends the comment, and the rest of the string is parsed as shell input: `quote(['echo', 'ok', { comment: 'x' }, 'a\nid;#'])` runs `id` in sh, bash, dash, ksh and zsh. `parse()` emits a comment token for a `#` in the middle of a word (for example `http://example.com/#frag`), so callers that combine `parse()` output with another untrusted string, such as `quote(parse(untrustedCommand).concat(untrustedArg))`, are affected. The fix for CVE-2026-9277 rejected line terminators in the comment's own text, but not in the tokens after it. Fixed in 1.11.0: `quote()` throws a `TypeError` when a string after a `{ comment }` token contains a line terminator.

Join the discussion
0

A security flaw has been discovered in REBUILD up to 4.4.11. This vulnerability affects unknown code of the file /commons/file-editor-save. The manipulation of the argument url/fileKey results in missing authorization. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.

Join the discussion

Flatpak's process ID namespace separation does not prevent a sandboxed app's kill(0, signal) or killpg(0, signal) calls from reaching processes outside the sandbox that share the same process group. A malicious or compromised Flatpak app can use this to cause denial of service by terminating processes outside its sandbox, such as the desktop shell.

Join the discussion

Showing 1 to 10 of 140227 results

Filters:Package: pkg:generic/binutils
Page 1 of 14023
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses