Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

CVE-2026-34641: Out-of-bounds Write (CWE-787) in Adobe PremiereCVE-2026-34641
0

Adobe Premiere Pro contains an out-of-bounds write vulnerability that may allow arbitrary code execution when a user opens a malicious file. Exploitation requires user interaction. The vulnerability has a high severity score of 7.8 and impacts confidentiality, integrity, and availability.

Join the discussion
CVE-2026-54785: CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in eLyiN gemini-bridgeCVE-2026-54785
0

A path traversal vulnerability (CWE-22) exists in eLyiN gemini-bridge versions prior to 1.3.1. The vulnerability allows an attacker to read arbitrary local files by supplying file paths outside the working directory to the consult_gemini_with_files function in inline mode. The contents of these files are then sent to Google's Gemini AI via the official CLI, potentially exposing sensitive local data. This issue is fixed in version 1.3.1.

Join the discussion
CVE-2026-9044: CWE-78 Improper neutralization of special elements used in an OS command ('OS command injection') in TP-Link Systems Inc. AXE75 V1CVE-2026-9044
0

An OS command injection vulnerability exists in the VPN module of TP-Link AXE75 V1 routers. An adjacent, authenticated attacker can exploit this by importing a specially crafted VPN client configuration file. This allows execution of arbitrary commands on the device, potentially leading to full device compromise affecting configuration, network security, and service availability.

Join the discussion
CVE-2026-54909: CWE-20: Improper Input Validation in pion stunCVE-2026-54909
0

A vulnerability in pion/stun, a Go implementation of STUN, allows remote denial of service due to improper input validation. Specifically, prior to version 3.1.3, the XORMappedAddress.GetFromAs function can panic when parsing a malformed short XOR-MAPPED-ADDRESS attribute in STUN or ICE Binding-response messages. This causes the application to crash. The issue is fixed in version 3.1.3.

Join the discussion
CVE-2026-54787: CWE-324: Use of a Key Past its Expiration Date in sigstore sigstore-goCVE-2026-54787
0

sigstore-go versions prior to 1.2.1 do not verify that a signing timestamp falls within the validity period of an ExpiringKey, allowing use of expired key material to sign bundles. This vulnerability is fixed in version 1.2.1.

Join the discussion
CVE-2026-53573: CWE-601: URL Redirection to Untrusted Site ('Open Redirect') in geonetwork core-geonetworkCVE-2026-53573
0

GeoNetwork core-geonetwork versions prior to 4.2.16 and 4.4.11 contain an open redirect vulnerability in the GeonetworkOAuth2LoginAuthenticationFilter and KeycloakAuthenticationProcessingFilter. This allows an attacker to control redirect URLs after login, potentially redirecting users to untrusted external sites. The vulnerability is fixed in versions 4.2.16 and 4.4.11.

Join the discussion
Amgen says cloud data breach exposed patient health, proprietary info
0

Amgen, a biotechnology company, experienced a data breach involving unauthorized access to corporate and patient data stored in multiple cloud systems managed by third-party providers. The breach was detected in July 2026, and the company responded by activating its cybersecurity response plan and engaging forensic experts. Stolen data includes proprietary information and protected health information. The investigation is ongoing, with no confirmed link to known threat actors or details on the extent of affected individuals. Amgen is evaluating legal notification requirements and has not reported any financial impact at this time.

MediumVulnerability
Join the discussion
CVE-2026-68771: Deserialization of Untrusted Data in Comfy-Org ComfyUICVE-2026-68771
0

ComfyUI version 0.23.0 contains a critical deserialization vulnerability in the LoadTrainingDataset node. This flaw allows unauthenticated remote attackers to execute arbitrary Python code by uploading a crafted pickle file via the unauthenticated POST /upload/image endpoint. When the uploaded file is referenced in a workflow graph queued via POST /prompt, the application deserializes the malicious pickle payload using torch.load, leading to code execution as the ComfyUI process user.

Join the discussion
CVE-2026-52371: n/aCVE-2026-52371
0

CVE-2026-52371 is a Server-Side Request Forgery (SSRF) vulnerability in the xxl-job component, specifically in the jobinfo/trigger interface of version 3.4.0. It allows authenticated attackers to scan internal or external resources by sending crafted HTTP requests. No CVSS score or patch information is currently available.

Join the discussion
CVE-2026-52232: n/aCVE-2026-52232
0

A reflected cross-site scripting (XSS) vulnerability exists in the /logo.asp component of FS Inc S3150-8T2F Switch version 2.2.0D Build 118101. This vulnerability allows attackers to execute arbitrary JavaScript in the context of a victim's browser via a crafted URL. The affected product is a cloud service. No CVSS score is provided for this vulnerability.

Join the discussion

Showing 1 to 10 of 22275 results

Filters:Package: pkg:generic/libultrahdr
Page 1 of 2228
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses