Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
CVE-2026-90685: Reachable Assertion in GPACCVE-2026-90685 0 A vulnerability has been found in GPAC up to f1219cde. Affected by this issue is the function lsr_exec_command_list of the file laser/lsr_dec.c of the component MP4Box. The manipulation leads to reachable assertion. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. Upgrading to version abi-16.23 can resolve this issue. The identifier of the patch is afca1f1181668d85941d51ed1adf647807d5d975. The affected component should be upgraded. Join the discussion | CVE Database V5 | 09/14/2026, 05:15:08 UTC Added: 09/14/2026, 05:32:01 UTC |
0 CVE-2026-90684 is a low-severity vulnerability in GPAC's MP4Box component, specifically in the function gf_node_get_field_count. It allows a reachable assertion to be triggered via local manipulation. The issue is fixed in GPAC version abi-16.23. Exploit code is publicly available but no known active exploitation is reported. Join the discussion | CVE Database V5 | 09/14/2026, 05:00:12 UTC Added: 09/14/2026, 05:17:41 UTC |
0 CVE-2026-90683 is a medium severity vulnerability in GPAC affecting the gf_node_unregister function in the MP4Box component. It causes a reachable assertion when manipulated locally. Exploit code is publicly available. Upgrading to version abi-16.23 addresses the issue. Join the discussion | CVE Database V5 | 09/14/2026, 04:45:12 UTC Added: 09/14/2026, 05:02:02 UTC |
CVE-2026-90682 is a heap-based buffer overflow vulnerability in the jhead tool by Matthias-Wandel, affecting versions 3.0 through 3.3. The flaw exists in the ProcessGpsInfo function within gpsinfo.c, specifically when handling the TAG_GPS_LAT and TAG_GPS_LONG arguments. Exploitation requires local access. The vulnerability has been publicly disclosed, but no vendor response or patch is currently available. Join the discussion | CVE Database V5 | 09/14/2026, 04:30:16 UTC Added: 09/14/2026, 04:47:08 UTC |
0 CVE-2026-90681 is an out-of-bounds read vulnerability in the Get16u function of the exif.c component in Matthias-Wandel jhead versions 3.0 through 3.3. This vulnerability requires local access to exploit and involves improper handling of EXIF parsing data. The vulnerability has a medium severity score of 4.8 and public exploit code is available. The vendor has been notified but has not yet responded or issued a fix. Join the discussion | CVE Database V5 | 09/14/2026, 04:15:11 UTC Added: 09/14/2026, 04:32:16 UTC |
CVE-2026-90623 is a medium severity vulnerability in andreashappe cochise versions 0.4.0 and 0.4.1. It involves improper certificate validation in the asyncssh.connect function within the SSH Host Key Handler component. The vulnerability can be exploited remotely but requires a high level of complexity and is difficult to exploit. No patch or vendor response has been reported yet. Join the discussion | CVE Database V5 | 09/14/2026, 03:45:13 UTC Added: 09/14/2026, 04:02:02 UTC |
0 CVE-2026-90620 is a medium severity vulnerability in 0x4m4 HexStrike AI causing missing authentication in an API command endpoint function within hexstrike_server.py. The flaw allows remote attackers to bypass authentication. The project uses continuous delivery with rolling releases, so no specific affected or fixed versions are identified. The vulnerability has been publicly disclosed, but no vendor response or patch is currently available. Join the discussion | CVE Database V5 | 09/14/2026, 03:00:11 UTC Added: 09/14/2026, 03:17:07 UTC |
The Android application "YAMAP -Social Trekking GPS App" by YAMAP INC. has an improper access control vulnerability in its WebView component. This flaw could potentially allow unauthorized access to certain app functionalities or data due to insufficient access restrictions in the WebView implementation. Join the discussion | JVN Japan | 09/14/2026, 03:00:00 UTC Added: 09/14/2026, 03:06:26 UTC |
0 CVE-2026-90619 is an OS command injection vulnerability in the 0x4m4 HexStrike AI product affecting an unknown function in hexstrike_server.py's Execute Endpoint component. The vulnerability arises from improper handling of the argument code/script, allowing remote attackers to inject OS commands. The product uses a rolling release model, so no specific affected or fixed versions are available. The vendor has been informed but has not yet responded or issued a fix. The vulnerability has a CVSS 4.0 score of 6.9 (medium severity). Join the discussion | CVE Database V5 | 09/14/2026, 02:45:12 UTC Added: 09/14/2026, 03:02:15 UTC |
CVE-2026-90618 is an OS command injection vulnerability in GH05TCREW PentestAgent affecting the LocalRuntime.execute_command function. The flaw allows remote attackers to execute arbitrary OS commands via crafted input. An exploit has been published, but the fix is pending acceptance in a pull request. Join the discussion | CVE Database V5 | 09/14/2026, 02:30:11 UTC Added: 09/14/2026, 02:47:03 UTC |
Showing 1 to 10 of 130752 results