Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
CVE-2026-75593: CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in moby buildkitCVE-2026-75593 0 BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. Prior to 0.31.2, a custom client can produce such an upload request to the BuildKit daemon that files can escape from the BuildKit-controlled state directory. The client needs to have valid permissions to access BuildKit control API to issue builds, eg., bypass authentication, etc. This issue is fixed in version 0.31.2. Join the discussion | CVE Database V5 | 08/19/2026, 20:06:54 UTC Added: 08/19/2026, 20:22:53 UTC |
CVE-2026-61712: CWE-770: Allocation of Resources Without Limits or Throttling in moby buildkitCVE-2026-61712 0 BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. Prior to 0.31.1, BuildKit read attacker-controlled /etc/passwd and /etc/group files without an upper bound while resolving a username to a user identifier or group identifier in executor/oci/user.go and solver/llbsolver/ops/user_linux.go. A malicious base image or build could provide oversized files that exhausted memory during user resolution and caused out-of-memory termination of the buildkitd process. This issue is fixed in version 0.31.1. Join the discussion | CVE Database V5 | 08/19/2026, 20:01:18 UTC Added: 08/19/2026, 20:22:53 UTC |
CVE-2026-61711: CWE-20: Improper Input Validation in moby buildkitCVE-2026-61711 0 BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. Prior to 0.31.1, a custom frontend could place an invalid SecurityMode value in a crafted build request, and executor/oci/spec_linux.go treated the unsupported value as a non-sandbox mode without requiring the security.insecure entitlement. This disabled Seccomp and AppArmor protections for the build container even though Linux capabilities remained restricted. This issue is fixed in version 0.31.1. Join the discussion | CVE Database V5 | 08/19/2026, 20:03:38 UTC Added: 08/19/2026, 20:22:53 UTC |
CVE-2026-54742: CWE-863: Incorrect Authorization in LemmyNet lemmyCVE-2026-54742 0 Lemmy is a link aggregator and forum for the fediverse. From 0.19.18 until 0.19.19 and 1.0.0-alpha.20, a community moderator can feature or unfeature posts in other communities through federated CollectionAdd and CollectionRemove activities using CollectionType::Featured. After verify_mod_action authorizes the actor against self.community(), the receive handlers in crates/apub/activities/src/community/collection_add.rs and crates/apub/activities/src/community/collection_remove.rs dereference self.object as an ApubPost and update featured_community without verifying that post.community_id equals community.id. A moderator can therefore target an unrelated post owned by another community, push it into featured feeds and listings, or undo another community's legitimate curation decision. This issue is fixed in versions 0.19.19 and 1.0.0-alpha.20. Join the discussion | CVE Database V5 | 08/19/2026, 20:10:56 UTC Added: 08/19/2026, 20:22:53 UTC |
CVE-2026-16707: CWE-125 Out-of-bounds Read in IBM PowerVM HypervisorCVE-2026-16707 0 IBM PowerVM Hypervisor FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW950.H2 is affected by a vulnerability in the service processor mailbox interface. An attacker with authenticated service-level access to the FSP can send a specially crafted mailbox message to read or modify arbitrary regions of Hostboot memory, compromising the host firmware boot stack and the hypervisor subsequently loaded by it. Successful exploitation results in a confidentiality, integrity, and availability impact to the managed system. Join the discussion | CVE Database V5 | 08/19/2026, 20:09:07 UTC Added: 08/19/2026, 20:22:53 UTC |
CVE-2026-76574: SQL Injection in code-projects Hospital Information SystemCVE-2026-76574 0 CVE-2026-76574 is a medium severity SQL injection vulnerability in code-projects Hospital Information System version 1.0. It affects the User::login function in includes/users/UsersController.php, allowing remote attackers to manipulate the email argument to perform SQL injection. Exploit code has been published, but no official patch or remediation guidance is currently available. Join the discussion | CVE Database V5 | 08/19/2026, 20:00:10 UTC Added: 08/19/2026, 20:07:54 UTC |
CVE-2026-16919: CWE-843 Access of Resource Using Incompatible Type ('Type Confusion') in IBM AIXCVE-2026-16919 0 CVE-2026-16919 is a critical vulnerability in IBM AIX versions 7.2 and 7.3, and IBM PowerVM VIOS 4.1. It involves improper validation of network-supplied pointers, leading to type confusion (CWE-843). This flaw could allow a remote attacker to execute arbitrary code without requiring user interaction or privileges. Join the discussion | CVE Database V5 | 08/19/2026, 19:57:23 UTC Added: 08/19/2026, 20:07:54 UTC |
CVE-2026-16917: CWE-190 Integer Overflow or Wraparound in IBM AIXCVE-2026-16917 0 CVE-2026-16917 is a critical integer overflow vulnerability in IBM AIX versions 7.2 and 7.3, and IBM PowerVM VIOS 4.1. This flaw could allow a remote attacker to execute arbitrary code without requiring user interaction or privileges. The vulnerability is due to an integer overflow or wraparound condition. No official patch or remediation information is currently provided by the vendor. The vulnerability has a CVSS score of 9.8, indicating a high impact on confidentiality, integrity, and availability. Join the discussion | CVE Database V5 | 08/19/2026, 19:56:57 UTC Added: 08/19/2026, 20:07:54 UTC |
CVE-2026-16914: CWE-787 Out-of-bounds Write in IBM AIXCVE-2026-16914 0 CVE-2026-16914 is an out-of-bounds write vulnerability in IBM AIX versions 7.2 and 7.3, as well as IBM PowerVM VIOS 4.1. This flaw could allow a local attacker with high privileges to execute arbitrary code on the affected systems. The vulnerability has a CVSS 3.1 base score of 6.7, indicating a medium severity level. No official patch or remediation guidance has been provided yet by IBM. There are no known exploits in the wild at this time. Join the discussion | CVE Database V5 | 08/19/2026, 19:56:39 UTC Added: 08/19/2026, 20:07:54 UTC |
CVE-2026-16913: CWE-787 Out-of-bounds Write in IBM AIXCVE-2026-16913 0 CVE-2026-16913 is a critical vulnerability in IBM AIX 7.2, 7.3, and IBM PowerVM VIOS 4.1 that allows a remote attacker to execute arbitrary code due to a stack buffer overflow. The flaw is classified as CWE-787 (Out-of-bounds Write). It has a CVSS v3.1 score of 9.8, indicating high severity with network attack vector, no privileges required, and no user interaction needed. Join the discussion | CVE Database V5 | 08/19/2026, 19:55:59 UTC Added: 08/19/2026, 20:07:52 UTC |
Showing 1 to 10 of 19790 results