Skip to main content

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Package: pkg:generic/libultrahdr

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

A vulnerability has been found in SourceCodester Online Faculty Clearance System 1.0. The impacted element is an unknown function of the file /delete_faculty1.php. Such manipulation of the argument ID leads to sql injection. The attack can be executed remotely. The exploit has been disclosed to the public and may be used.

Join the discussion

The WP Directory Kit WordPress plugin through 1.5.7 does not check the status or ownership of a listing before returning its content through one of its public AJAX actions, allowing unauthenticated attackers to read draft and unapproved listings belonging to other users.

Join the discussion

The WP Directory Kit WordPress plugin through 1.5.7 does not check authorization or listing visibility in one of its shortcodes, allowing users with a role as low as Contributor to disclose non-public listing content, including password-protected and hidden fields, belonging to other users.

Join the discussion

The WP Directory Kit WordPress plugin through 1.5.7 does not sanitize and escape some widget settings before using them in a SQL statement, allowing authenticated users with access to the page builder (Editor and above) to perform SQL injection attacks that execute when the affected page is rendered.

Join the discussion

Android application "ManabiPocket for Parents" contains an improper access control vulnerability in one of its components. A malicious application installed on the user's Android device may exploit the affected component via an Intent, potentially allowing the malicious application to obtain sensitive information from the affected application.

Join the discussion

A flaw has been found in D-Link DI-8300 16.07. The affected element is the function rzgl_asp of the file /rzgl.asp of the component CGI Service. This manipulation of the argument redirct_url causes stack-based buffer overflow. Remote exploitation of the attack is possible. The exploit has been published and may be used.

Join the discussion

CVE-2026-81320 is a vulnerability in the hawtio-operator component of the Red Hat build of Apache Camel - HawtIO 4. When a custom Route TLS secret is configured and the operator runs at debug log level 1 or higher, the operator logs the entire Route object including the TLS private key in PEM format to standard output. These logs are typically forwarded to centralized logging systems accessible to users with pods/log access in the openshift-operators namespace. This exposure can allow attackers with log access to obtain private keys, potentially enabling impersonation or decryption of traffic. The vulnerability has a medium severity with a CVSS score of 5.5. Mitigation involves setting the operator log verbosity to 0 (default) to prevent logging sensitive key material and rotating any TLS secrets exposed if debug logging was previously enabled.

Join the discussion

CVE-2026-81303 is a medium severity vulnerability in the hawtio-operator component of the Red Hat build of Apache Camel - HawtIO 4. The operator improperly writes tenant-supplied hostnames into OpenShift Route specifications without validating authorization, allowing a namespace edit user to claim arbitrary externally-routable hostnames. This confused deputy flaw can enable subdomain takeover and, when combined with other issues, OAuth redirect hijacking. Mitigations include restricting creation/modification of Hawtio custom resources via RBAC and configuring route admission policies to reject unauthorized hostnames.

Join the discussion

CVE-2026-91002 is a medium severity vulnerability in stamparm maltrail up to version 3.0.1. It affects the _blacklist function in the core/httpd.py file, allowing remote attackers to bypass authentication. The issue was fixed in version 3.1 by requiring authenticated sessions or using the Blacklist_ALLOWLIST option.

Join the discussion

A vulnerability in the email parsing of Cisco AsyncOS Software for Cisco Secure Email Gateway could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileges on the underlying operating system. This vulnerability is due to insufficient validation in the email parsing logic. An attacker could exploit this vulnerability by sending a crafted email message that contains malicious SQL statements through an affected device. A successful exploit could allow the attacker to execute arbitrary SQL statements, leading to command execution with root privileges on the underlying operating system.

Join the discussion

Showing 1 to 10 of 131710 results

Filters:Package: pkg:generic/libultrahdr
Page 1 of 13171
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses