Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
In WhatsUp Gold versions released before 2026.0.2, a privileged attacker can write arbitrary files to a web-accessible location on the host server. (CVE-2026-65940)CVE-2026-65940 0 In WhatsUp Gold versions released before 2026.0.2, a privileged attacker can write arbitrary files to a web-accessible location on the host server. Join the discussion | GCVE Database | 08/12/2026, 18:31:18 UTC Added: 08/12/2026, 20:13:30 UTC |
An unauthenticated attacker may cause untrusted package content to be cached under specific conditions, potentially affecting artifact integrity and… (CVE-2026-69105)CVE-2026-69105 0 An unauthenticated attacker may cause untrusted package content to be cached under specific conditions, potentially affecting artifact integrity and availability. Join the discussion | GCVE Database | 08/12/2026, 18:31:19 UTC Added: 08/12/2026, 20:13:30 UTC |
Apache Airflow's asset materialization endpoint (POST /api/v2/assets/{asset_id}/materialize) and the XCom result check on… (CVE-2026-68971)CVE-2026-68971 0 Apache Airflow's asset materialization endpoint (`POST /api/v2/assets/{asset_id}/materialize`) and the XCom result check on `wait_dag_run_until_finished` authorized the target Dag without its team, unlike every other authorization site. A team-aware auth manager distinguishes a team-scoped Dag from a global one by that field -- the Keycloak auth manager, for example, checks the `DAG` resource instead of `DAG:<team>` -- so the team-scoped permission that should gate the request was never consulted. In a deployment running multi-team mode with a team-aware auth manager, an authenticated user in one team could trigger Dag runs belonging to another team, supplying their own `dag_run_id` and `conf`, and could read another team's XCom values. Deployments using the FAB auth manager are unaffected, as it has no multi-team support. Users are advised to upgrade to apache-airflow 3.3.1 or later, which resolves the Dag's team at both sites. Join the discussion | GCVE Database | 08/12/2026, 18:31:19 UTC Added: 08/12/2026, 20:13:30 UTC |
IBM i 7.6, 7.5, 7.4, and 7.3 is vulnerable to stored cross-site scripting. (CVE-2026-16694)CVE-2026-16694 0 IBM i 7.6, 7.5, 7.4, and 7.3 is vulnerable to stored cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. Join the discussion | GCVE Database | 08/12/2026, 18:31:19 UTC Added: 08/12/2026, 20:13:30 UTC |
Apache Airflow wrote Variable values and Connection extra contents to the audit log in cleartext when they were submitted through the bulk endpoints… (CVE-2026-68969)CVE-2026-68969 0 Apache Airflow wrote Variable values and Connection `extra` contents to the audit log in cleartext when they were submitted through the bulk endpoints (`PATCH /api/v2/variables` and `PATCH /api/v2/connections`). The audit-log masking recognised only top-level request fields, and a bulk request nests its entities two levels below, so no masking was applied to them. Any authenticated user with audit-log read access -- who need not hold Variables or Connections read at all -- could recover those secrets verbatim, and the Connection `extra` copy is stored unencrypted in the log while the connection table encrypts it. The Airflow UI's *Import Variables* action posts to this endpoint, so an ordinary operator import wrote every secret in the file to the log. This is a different code path from CVE-2026-50204: that fix shipped in 3.3.0 and covers the single-entity endpoints only, so deployments that upgraded in response to that advisory remain affected and must upgrade again. Users are advised to upgrade to apache-airflow 3.3.1 or later. Join the discussion | GCVE Database | 08/12/2026, 18:31:19 UTC Added: 08/12/2026, 20:13:30 UTC |
Apache Airflow's Task SDK did not mask the contents of a Variable whose JSON value is a list, so secrets stored in that shape appeared in cleartext… (CVE-2026-68970)CVE-2026-68970 0 Apache Airflow's Task SDK did not mask the contents of a Variable whose JSON value is a list, so secrets stored in that shape appeared in cleartext in task logs and in the Rendered Templates UI. Masking was applied only when the deserialized value was a string or a dict; a list at the top level matched neither and was returned unmasked. Any authenticated user able to read the logs or rendered templates of a task that references such a Variable could recover the values, with no special configuration required. This is the list-shaped counterpart of CVE-2026-59244, whose fix covered the dict case only, so deployments that upgraded in response to that advisory remain affected and must upgrade again. Users are advised to upgrade to apache-airflow 3.3.1 or later. Join the discussion | GCVE Database | 08/12/2026, 18:31:19 UTC Added: 08/12/2026, 20:13:30 UTC |
An unauthenticated user may access restricted artifacts in JFrog Artifactory under specific conditions. (CVE-2026-69107)CVE-2026-69107 0 An unauthenticated user may access restricted artifacts in JFrog Artifactory under specific conditions. Join the discussion | GCVE Database | 08/12/2026, 18:31:19 UTC Added: 08/12/2026, 20:13:30 UTC |
An authenticated user without repository read permission may access package metadata under specific conditions. (CVE-2026-70547)CVE-2026-70547 0 An authenticated user without repository read permission may access package metadata under specific conditions. Join the discussion | GCVE Database | 08/12/2026, 18:31:19 UTC Added: 08/12/2026, 20:13:30 UTC |
XSS vulnerability in code display in Apache Allura. (CVE-2026-73238)CVE-2026-73238 0 XSS vulnerability in code display in Apache Allura. This issue affects Apache Allura: before 1.19.1. Users are recommended to upgrade to version 1.19.1, which fixes the issue. Join the discussion | GCVE Database | 08/12/2026, 18:31:20 UTC Added: 08/12/2026, 20:13:30 UTC |
Specifically crafted inputs may lead to git argument injection in Apache Allura. (CVE-2026-73240)CVE-2026-73240 0 Specifically crafted inputs may lead to git argument injection in Apache Allura. This issue affects Apache Allura: before 1.19.1. Users are recommended to upgrade to version 1.19.1, which fixes the issue. Join the discussion | GCVE Database | 08/12/2026, 18:31:20 UTC Added: 08/12/2026, 20:13:30 UTC |
Showing 1 to 10 of 24169 results