Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

CVE-2026-75593: CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in moby buildkitCVE-2026-75593
0

BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. Prior to 0.31.2, a custom client can produce such an upload request to the BuildKit daemon that files can escape from the BuildKit-controlled state directory. The client needs to have valid permissions to access BuildKit control API to issue builds, eg., bypass authentication, etc. This issue is fixed in version 0.31.2.

Join the discussion
CVE-2026-61712: CWE-770: Allocation of Resources Without Limits or Throttling in moby buildkitCVE-2026-61712
0

BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. Prior to 0.31.1, BuildKit read attacker-controlled /etc/passwd and /etc/group files without an upper bound while resolving a username to a user identifier or group identifier in executor/oci/user.go and solver/llbsolver/ops/user_linux.go. A malicious base image or build could provide oversized files that exhausted memory during user resolution and caused out-of-memory termination of the buildkitd process. This issue is fixed in version 0.31.1.

Join the discussion
CVE-2026-61711: CWE-20: Improper Input Validation in moby buildkitCVE-2026-61711
0

BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. Prior to 0.31.1, a custom frontend could place an invalid SecurityMode value in a crafted build request, and executor/oci/spec_linux.go treated the unsupported value as a non-sandbox mode without requiring the security.insecure entitlement. This disabled Seccomp and AppArmor protections for the build container even though Linux capabilities remained restricted. This issue is fixed in version 0.31.1.

Join the discussion
CVE-2026-54742: CWE-863: Incorrect Authorization in LemmyNet lemmyCVE-2026-54742
0

Lemmy is a link aggregator and forum for the fediverse. From 0.19.18 until 0.19.19 and 1.0.0-alpha.20, a community moderator can feature or unfeature posts in other communities through federated CollectionAdd and CollectionRemove activities using CollectionType::Featured. After verify_mod_action authorizes the actor against self.community(), the receive handlers in crates/apub/activities/src/community/collection_add.rs and crates/apub/activities/src/community/collection_remove.rs dereference self.object as an ApubPost and update featured_community without verifying that post.community_id equals community.id. A moderator can therefore target an unrelated post owned by another community, push it into featured feeds and listings, or undo another community's legitimate curation decision. This issue is fixed in versions 0.19.19 and 1.0.0-alpha.20.

Join the discussion
CVE-2026-16707: CWE-125 Out-of-bounds Read in IBM PowerVM HypervisorCVE-2026-16707
0

IBM PowerVM Hypervisor FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW950.H2 is affected by a vulnerability in the service processor mailbox interface. An attacker with authenticated service-level access to the FSP can send a specially crafted mailbox message to read or modify arbitrary regions of Hostboot memory, compromising the host firmware boot stack and the hypervisor subsequently loaded by it. Successful exploitation results in a confidentiality, integrity, and availability impact to the managed system.

Join the discussion
CVE-2026-76574: SQL Injection in code-projects Hospital Information SystemCVE-2026-76574
0

CVE-2026-76574 is a medium severity SQL injection vulnerability in code-projects Hospital Information System version 1.0. It affects the User::login function in includes/users/UsersController.php, allowing remote attackers to manipulate the email argument to perform SQL injection. Exploit code has been published, but no official patch or remediation guidance is currently available.

Join the discussion
CVE-2026-16919: CWE-843 Access of Resource Using Incompatible Type ('Type Confusion') in IBM AIXCVE-2026-16919
0

CVE-2026-16919 is a critical vulnerability in IBM AIX versions 7.2 and 7.3, and IBM PowerVM VIOS 4.1. It involves improper validation of network-supplied pointers, leading to type confusion (CWE-843). This flaw could allow a remote attacker to execute arbitrary code without requiring user interaction or privileges.

Join the discussion
CVE-2026-16917: CWE-190 Integer Overflow or Wraparound in IBM AIXCVE-2026-16917
0

CVE-2026-16917 is a critical integer overflow vulnerability in IBM AIX versions 7.2 and 7.3, and IBM PowerVM VIOS 4.1. This flaw could allow a remote attacker to execute arbitrary code without requiring user interaction or privileges. The vulnerability is due to an integer overflow or wraparound condition. No official patch or remediation information is currently provided by the vendor. The vulnerability has a CVSS score of 9.8, indicating a high impact on confidentiality, integrity, and availability.

Join the discussion
CVE-2026-16914: CWE-787 Out-of-bounds Write in IBM AIXCVE-2026-16914
0

CVE-2026-16914 is an out-of-bounds write vulnerability in IBM AIX versions 7.2 and 7.3, as well as IBM PowerVM VIOS 4.1. This flaw could allow a local attacker with high privileges to execute arbitrary code on the affected systems. The vulnerability has a CVSS 3.1 base score of 6.7, indicating a medium severity level. No official patch or remediation guidance has been provided yet by IBM. There are no known exploits in the wild at this time.

Join the discussion
CVE-2026-16913: CWE-787 Out-of-bounds Write in IBM AIXCVE-2026-16913
0

CVE-2026-16913 is a critical vulnerability in IBM AIX 7.2, 7.3, and IBM PowerVM VIOS 4.1 that allows a remote attacker to execute arbitrary code due to a stack buffer overflow. The flaw is classified as CWE-787 (Out-of-bounds Write). It has a CVSS v3.1 score of 9.8, indicating high severity with network attack vector, no privileges required, and no user interaction needed.

Join the discussion

Showing 1 to 10 of 19790 results

Filters:Package: pkg:generic/opensips
Page 1 of 1979
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses