Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
CVE-2026-71624: n/aCVE-2026-71624 0 An issue in esoTalk v.1.0.0g4 allows a remote attacker to execute arbitrary code via the core/models/ETMemberModel.class.php, core/controllers/ETMemberController.class.php, and core/lib/ET.class.php components Join the discussion | CVE Database V5 | 09/04/2026, 00:00:00 UTC Added: 09/04/2026, 19:37:48 UTC |
CVE-2026-71622: n/aCVE-2026-71622 0 SQL injection vulnerability in Zhao-github APiAdmin v.5.0.1 allows a remote attacker to obtain sensitive information via the User.php component Join the discussion | CVE Database V5 | 09/04/2026, 00:00:00 UTC Added: 09/04/2026, 19:37:48 UTC |
CVE-2026-85643: SQL Injection in code-projects Online Shopping SystemCVE-2026-85643 0 A flaw has been found in code-projects Online Shopping System 1.0. Impacted is the function mysqli_query of the file admin/adduser.php. Executing a manipulation of the argument mobile can lead to sql injection. The attack may be performed from remote. The exploit has been published and may be used. Join the discussion | CVE Database V5 | 09/04/2026, 19:15:08 UTC Added: 09/04/2026, 19:22:41 UTC |
CVE-2026-78839: n/aCVE-2026-78839 0 An arbitrary file upload vulnerability in AppNitro MachForm v30 allows attackers to execute arbitrary code via uploading a crafted .phar file. Join the discussion | CVE Database V5 | 09/04/2026, 00:00:00 UTC Added: 09/04/2026, 19:07:47 UTC |
CVE-2026-85639: Race Condition in jofpin trapeCVE-2026-85639 0 A security vulnerability has been detected in jofpin trape 2.0. This vulnerability affects unknown code of the file core/user.py of the component Telemetry Endpoint. Such manipulation of the argument vId leads to race condition. The attack can be executed remotely. Attacks of this nature are highly complex. It is stated that the exploitability is difficult. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through an issue report but has not responded yet. Join the discussion | CVE Database V5 | 09/04/2026, 19:00:08 UTC Added: 09/04/2026, 19:07:47 UTC |
CVE-2026-71620: n/aCVE-2026-71620 0 File Upload vulnerability in Zhao-github ApiAdmin v.5.0.1 allows a remote attacker to execute arbitrary code via a crafted .php file Join the discussion | CVE Database V5 | 09/04/2026, 00:00:00 UTC Added: 09/04/2026, 19:07:47 UTC |
CVE-2026-80119: External Control of File Name or Path in PassMark Software PerformanceTestCVE-2026-80119 0 PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 1000, and OSForensics before 11.1 build 1016 contain an information disclosure vulnerability in DirectIo64.sys that allows unauthenticated local attackers to dump complete physical memory contents by supplying a caller-controlled file path to an exposed IOCTL. Attackers can issue a single IOCTL call to trigger the driver to iterate all physical memory ranges via MmGetPhysicalMemoryRanges and map each page through ZwMapViewOfSection on the PhysicalMemory section object, writing a full RAM image to an attacker-specified path in the SYSTEM context, bypassing user-mode ACLs and exposing LSASS working set, process memory, and cryptographic material from all running processes. Join the discussion | CVE Database V5 | 09/04/2026, 18:37:58 UTC Added: 09/04/2026, 18:52:41 UTC |
CVE-2026-80118: NULL Pointer Dereference in PassMark Software PerformanceTestCVE-2026-80118 0 PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 1000, and OSForensics before 11.1 build 1016 contain an unauthenticated physical memory disclosure in DirectIo64.sys, reachable by unprivileged local users through a single IOCTL with no caller-identity check. The handler writes a crash-dump-format (PAGEDU64) image of all physical memory to a caller-supplied file path in the SYSTEM context, allowing a standard user to create files in locations they cannot otherwise write and to recover memory belonging to processes of other users. The image is preceded by a header that exposes the kernel loaded-module list, active-process list and PFN database pointers, defeating KASLR. The same handler also dereferences the return value of an internal kernel-structure locator without a NULL check; that locator returns NULL on three distinct failure paths, and a kernel crash results on builds where any of those paths is taken. Join the discussion | CVE Database V5 | 09/04/2026, 18:37:15 UTC Added: 09/04/2026, 18:52:41 UTC |
CVE-2026-85781: CWE-283 Unverified ownership in aws aws-efs-csi-driverCVE-2026-85781 0 Unverified ownership of a storage access point in the volume deletion component of the Amazon EFS CSI Driver before v3.4.1 might allow an authenticated Kubernetes user with PersistentVolume creation privileges to cause recursive deletion of directories on an EFS filesystem they are not authorized to access, via a crafted PersistentVolume volumeHandle that pairs an access point from one filesystem with a different target filesystem. To remediate this issue, users should upgrade to version v3.4.1. Join the discussion | CVE Database V5 | 09/04/2026, 18:49:53 UTC Added: 09/04/2026, 18:52:41 UTC |
CVE-2026-85638: Authorization Bypass in jofpin trapeCVE-2026-85638 0 A weakness has been identified in jofpin trape 2.0. This affects an unknown part of the file core/user.py. This manipulation of the argument vId/id causes authorization bypass. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet. Join the discussion | CVE Database V5 | 09/04/2026, 18:45:07 UTC Added: 09/04/2026, 18:52:41 UTC |
Showing 1 to 10 of 17727 results