Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
CVE-2026-18673: CWE-200 Exposure of Sensitive Information to an Unauthorized Actor in Kong Inc. Kong MeshCVE-2026-18673 0 When kuma-dp is configured with the Envoy admin API on a Unix domain socket, which is the default, its readiness service on TCP port 9902 - bound to all interfaces - forwards almost the entire Envoy admin API to any caller that can reach the port, with no authentication. An attacker with network access to a data plane's port 9902, for example another pod on the cluster network, can read Envoy and data plane configuration without credentials: config dumps, cluster and listener lists, stats, and the mesh trust bundle. Exposure is read-only - destructive Envoy admin actions are blocked and private keys are not exposed. Join the discussion | CVE Database V5 | 08/12/2026, 18:20:33 UTC Added: 08/12/2026, 18:41:44 UTC |
CVE-2026-73327: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in Joomla Joomla! CMSCVE-2026-73327 0 Joomla 6.1.1 contains a path traversal vulnerability in the com_joomlaupdate extension. This flaw allows a Super User to be tricked into extracting a specially crafted archive with directory traversal sequences or absolute paths in ZIP entry filenames. Exploitation can lead to files being written outside the intended directory, enabling persistent remote code execution through planted PHP files. The vulnerability has a high severity score of 8.7 but no official patch or remediation guidance is currently confirmed. Join the discussion | CVE Database V5 | 08/12/2026, 18:05:19 UTC Added: 08/12/2026, 18:12:20 UTC |
Seeking Advice on Career Pivot: Transitioning from Backend to Offensive Cybersecurity 0 This content is a Reddit post where an individual seeks advice on transitioning from a backend development career to offensive cybersecurity. The post includes personal background, career concerns, goals for relocation, and a list of self-study resources. It is not a security threat or vulnerability but rather a career discussion. Join the discussion | Reddit Cybersecurity | 08/12/2026, 18:00:08 UTC Added: 08/12/2026, 18:11:05 UTC |
CVE-2026-73299: CWE-94: Improper Control of Generation of Code ('Code Injection') in microsoft promptyCVE-2026-73299 0 CVE-2026-73299 is a critical code injection vulnerability in Microsoft Prompty, a markdown file format for LLM prompts. Versions prior to 0.1.5 and 2.0.0-beta.5 of the TypeScript Nunjucks renderer allowed untrusted .prompty templates to execute arbitrary JavaScript code by traversing constructor and prototype properties. This could lead to full compromise of the host Node.js process. The issue is fixed in versions 0.1.5 and 2.0.0-beta.5. Join the discussion | CVE Database V5 | 08/12/2026, 17:31:38 UTC Added: 08/12/2026, 17:56:56 UTC |
CVE-2026-73298: CWE-639: Authorization Bypass Through User-Controlled Key in microsoft Container-Migration-Solution-AcceleratorCVE-2026-73298 0 CVE-2026-73298 is a high-severity authorization bypass vulnerability in Microsoft Container Migration Solution Accelerator version 2.1.2 and earlier. It allows authenticated users to bypass ownership checks and read, write, or delete processes and files belonging to other authenticated users within the same organization. The vulnerability affects multiple API endpoints related to process and file management. Although the application uses Entra ID for authentication, it lacks proper authorization controls between users. This issue is classified as an Insecure Direct Object Reference (IDOR) and is present in a cloud-hosted service. Join the discussion | CVE Database V5 | 08/12/2026, 17:24:56 UTC Added: 08/12/2026, 17:56:56 UTC |
CVE-2026-69106: CWE-20 Improper Input Validation in jfrog artifactoryCVE-2026-69106 0 CVE-2026-69106 is a high-severity vulnerability in JFrog Artifactory where a low-privileged user can poison cached artifact metadata under certain conditions. This may lead to consumers retrieving untrusted content, impacting confidentiality, integrity, and availability. Join the discussion | CVE Database V5 | 08/12/2026, 17:48:29 UTC Added: 08/12/2026, 17:56:56 UTC |
CVE-2026-42018: CWE-287 Improper Authentication in jfrog artifactoryCVE-2026-42018 0 JFrog Artifactory has a vulnerability where it may return an internal anonymous-user token to unauthenticated callers even when anonymous access is disabled. This improper authentication issue could expose sensitive resources to unauthorized users. The vulnerability is identified as CWE-287 and has a high severity with a CVSS score of 7.5. Join the discussion | CVE Database V5 | 08/12/2026, 17:43:21 UTC Added: 08/12/2026, 17:56:56 UTC |
CVE-2026-18669: CWE-250 Execution with Unnecessary PrivilegesCVE-2026-18669 0 IBM i versions 7.3, 7.4, 7.5, and 7.6 contain a vulnerability in the activation engine component that allows an authenticated attacker to execute a malicious script with root privileges. This privilege escalation occurs due to execution with unnecessary privileges, enabling full system compromise. The vulnerability has a high severity score of 8.8 and does not currently have an official patch or remediation guidance publicly available. Join the discussion | CVE Database V5 | 08/12/2026, 17:32:05 UTC Added: 08/12/2026, 17:56:56 UTC |
CVE-2026-17420: CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')CVE-2026-17420 0 IBM i versions 7.3, 7.4, 7.5, and 7.6 contain a vulnerability where improper neutralization of special elements in an SQL parameter could allow a remote authenticated attacker to bypass security restrictions. This vulnerability is classified as OS Command Injection (CWE-78). The CVSS score is 6.3, indicating a medium severity level. Join the discussion | CVE Database V5 | 08/12/2026, 17:25:50 UTC Added: 08/12/2026, 17:56:56 UTC |
CVE-2026-17271: CWE-770 Allocation of Resources Without Limits or ThrottlingCVE-2026-17271 0 IBM i versions 7.3, 7.4, 7.5, and 7.6 contain a vulnerability (CVE-2026-17271) where improper validation of input size could allow a remote attacker to cause a denial of service by allocating resources without limits or throttling. Join the discussion | CVE Database V5 | 08/12/2026, 17:35:22 UTC Added: 08/12/2026, 17:56:56 UTC |
Showing 1 to 10 of 24064 results