Skip to main content

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Package: pkg:generic/hdf5

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

0

A vulnerability has been found in GPAC up to f1219cde. Affected by this issue is the function lsr_exec_command_list of the file laser/lsr_dec.c of the component MP4Box. The manipulation leads to reachable assertion. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. Upgrading to version abi-16.23 can resolve this issue. The identifier of the patch is afca1f1181668d85941d51ed1adf647807d5d975. The affected component should be upgraded.

Join the discussion
0

CVE-2026-90684 is a low-severity vulnerability in GPAC's MP4Box component, specifically in the function gf_node_get_field_count. It allows a reachable assertion to be triggered via local manipulation. The issue is fixed in GPAC version abi-16.23. Exploit code is publicly available but no known active exploitation is reported.

Join the discussion
0

CVE-2026-90683 is a medium severity vulnerability in GPAC affecting the gf_node_unregister function in the MP4Box component. It causes a reachable assertion when manipulated locally. Exploit code is publicly available. Upgrading to version abi-16.23 addresses the issue.

Join the discussion

CVE-2026-90682 is a heap-based buffer overflow vulnerability in the jhead tool by Matthias-Wandel, affecting versions 3.0 through 3.3. The flaw exists in the ProcessGpsInfo function within gpsinfo.c, specifically when handling the TAG_GPS_LAT and TAG_GPS_LONG arguments. Exploitation requires local access. The vulnerability has been publicly disclosed, but no vendor response or patch is currently available.

Join the discussion

CVE-2026-90681 is an out-of-bounds read vulnerability in the Get16u function of the exif.c component in Matthias-Wandel jhead versions 3.0 through 3.3. This vulnerability requires local access to exploit and involves improper handling of EXIF parsing data. The vulnerability has a medium severity score of 4.8 and public exploit code is available. The vendor has been notified but has not yet responded or issued a fix.

Join the discussion

CVE-2026-90623 is a medium severity vulnerability in andreashappe cochise versions 0.4.0 and 0.4.1. It involves improper certificate validation in the asyncssh.connect function within the SSH Host Key Handler component. The vulnerability can be exploited remotely but requires a high level of complexity and is difficult to exploit. No patch or vendor response has been reported yet.

Join the discussion

CVE-2026-90620 is a medium severity vulnerability in 0x4m4 HexStrike AI causing missing authentication in an API command endpoint function within hexstrike_server.py. The flaw allows remote attackers to bypass authentication. The project uses continuous delivery with rolling releases, so no specific affected or fixed versions are identified. The vulnerability has been publicly disclosed, but no vendor response or patch is currently available.

Join the discussion

The Android application "YAMAP -Social Trekking GPS App" by YAMAP INC. has an improper access control vulnerability in its WebView component. This flaw could potentially allow unauthorized access to certain app functionalities or data due to insufficient access restrictions in the WebView implementation.

MediumVulnerability#android
Join the discussion

CVE-2026-90619 is an OS command injection vulnerability in the 0x4m4 HexStrike AI product affecting an unknown function in hexstrike_server.py's Execute Endpoint component. The vulnerability arises from improper handling of the argument code/script, allowing remote attackers to inject OS commands. The product uses a rolling release model, so no specific affected or fixed versions are available. The vendor has been informed but has not yet responded or issued a fix. The vulnerability has a CVSS 4.0 score of 6.9 (medium severity).

Join the discussion

CVE-2026-90618 is an OS command injection vulnerability in GH05TCREW PentestAgent affecting the LocalRuntime.execute_command function. The flaw allows remote attackers to execute arbitrary OS commands via crafted input. An exploit has been published, but the fix is pending acceptance in a pull request.

Join the discussion

Showing 1 to 10 of 130752 results

Filters:Package: pkg:generic/hdf5
Page 1 of 13076
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses