Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
CVE-2026-78212: CWE-23 Relative Path Traversal in 4MOSAn Security Technology 4MOSAn Management CenterCVE-2026-78212 0 4MOSAn developed by 4MOSAn Security Technology Co., Ltd. has an Arbitrary File Read vulnerability. Unauthenticated remote attackers can exploit a Relative Path Traversal flaw to download arbitrary system files. Join the discussion | CVE Database V5 | 08/24/2026, 03:36:28 UTC Added: 08/24/2026, 03:52:52 UTC |
CVE-2026-78211: CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in 4MOSAn Security Technology 4MOSAn GCB DoctorCVE-2026-78211 0 4MOSAn GCB Doctor developed by 4MOSAn Security Technology has a OS Command Injection vulnerability. Unauthenticated remote attackers can inject malicious commands through an unremoved ADOdb test page parameter, thereby executing arbitrary system commands on the server. Join the discussion | CVE Database V5 | 08/24/2026, 03:32:54 UTC Added: 08/24/2026, 03:52:52 UTC |
CVE-2026-78182: SQL Injection in Shenzhen Gongji Technology XBROTHER Dynamic Environment Monitoring SystemCVE-2026-78182 0 A security vulnerability has been detected in Shenzhen Gongji Technology XBROTHER Dynamic Environment Monitoring System up to 300R004C00B300. The affected element is the function PlanController.getImmediatePlans of the file /xbreport/api/v1/plamange/plansImmediate. The manipulation of the argument order/sort leads to sql injection. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used. Join the discussion | CVE Database V5 | 08/24/2026, 03:45:36 UTC Added: 08/24/2026, 03:52:52 UTC |
CVE-2026-78181: Improperly Controlled Modification of Object Prototype Attributes in ractivejs ractiveCVE-2026-78181 0 A weakness has been identified in ractivejs ractive up to 1.4.4. Impacted is the function Ractive#set of the component Keypath Handler. Executing a manipulation can lead to improperly controlled modification of object prototype attributes. The attack may be launched remotely. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet. Join the discussion | CVE Database V5 | 08/24/2026, 03:30:08 UTC Added: 08/24/2026, 03:52:52 UTC |
CVE-2026-19853: CWE-306 Missing Authentication for Critical Function in CyberTutor NewSiteServer (NSS)CVE-2026-19853 0 NewSiteServer (NSS) developed by CyberTutor has a Missing Authentication vulnerability. Unauthenticated remote attackers can exploit a specific functionality to send emails to anyone on behalf of the school. Join the discussion | CVE Database V5 | 08/24/2026, 03:30:35 UTC Added: 08/24/2026, 03:52:52 UTC |
CVE-2026-19852: CWE-434 Unrestricted Upload of File with Dangerous Type in CyberTutor NewSiteServer (NSS)CVE-2026-19852 0 NewSiteServer (NSS) developed by CyberTutor has an Arbitrary File Upload vulnerability. Unauthenticated remote attackers can upload arbitrary files, including malicious HTML files, thereby achieving effects similar to cross-site scripting. Join the discussion | CVE Database V5 | 08/24/2026, 03:35:01 UTC Added: 08/24/2026, 03:52:52 UTC |
CVE-2026-78180: Improperly Controlled Modification of Object Prototype Attributes in alibaba-fusion nextCVE-2026-78180 0 CVE-2026-78180 is a medium severity vulnerability in alibaba-fusion next up to version 1.27.34. It involves improper control of object prototype attribute modification via manipulation of the locale argument in the ConfigProvider.getContextProps function. This flaw affects the deepMerge component in components/dialog/index.tsx and can be triggered remotely without authentication. Join the discussion | CVE Database V5 | 08/24/2026, 03:15:08 UTC Added: 08/24/2026, 03:37:52 UTC |
CVE-2026-78179: Improperly Controlled Modification of Object Prototype Attributes in rexrainbow phaser3-rex-notesCVE-2026-78179 0 A vulnerability was identified in rexrainbow phaser3-rex-notes up to 1.80.17. This vulnerability affects the function SetValue of the file plugins/utils/object/SetValue.js of the component BehaviorTree Blackboard Data Interface. Such manipulation of the argument key leads to improperly controlled modification of object prototype attributes. The attack can be launched remotely. Join the discussion | CVE Database V5 | 08/24/2026, 03:00:08 UTC Added: 08/24/2026, 03:37:52 UTC |
CVE-2026-19200: CWE-862: Missing Authorization in Rapid7 VelociraptorCVE-2026-19200 0 CVE-2026-19200 is a high-severity vulnerability in Rapid7 Velociraptor versions prior to 0.77.2. It involves a missing authorization check in the verify() VQL function, which allows users with NOTEBOOK_EDIT permission to overwrite existing artifacts in the global artifact repository without proper permissions. This flaw can lead to significant confidentiality, integrity, and availability impacts. Join the discussion | CVE Database V5 | 08/24/2026, 03:22:14 UTC Added: 08/24/2026, 03:37:52 UTC |
Sakura Editor vulnerable to OS command injection 0 Sakura Editor, a text editor developed by the Sakura Editor Development Community, contains an OS command injection vulnerability. This flaw allows an attacker to execute arbitrary operating system commands via the application. No specific affected versions or patch information is provided. There are no known exploits in the wild at this time. HighVulnerability Join the discussion | JVN Japan | 08/24/2026, 03:00:00 UTC Added: 08/24/2026, 03:08:54 UTC |
Showing 1 to 10 of 17848 results