Skip to main content

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Package: pkg:generic/p11-kit

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

a-blog cms, a content management system provided by appleple inc., contains a path traversal vulnerability. This vulnerability could allow unauthorized access to files outside the intended directory structure.

MediumVulnerability
Join the discussion

Brainzcompany Zenius EMS 8.0 contains an authentication bypass vulnerability via an alternate path or channel, combined with improper validation of input syntax. This flaw allows remote code inclusion, potentially enabling attackers to execute arbitrary code remotely. The vulnerability affects Zenius EMS 8.0 through OAM (Build 109).

Join the discussion

This entry is a daily update from the SANS Internet Storm Center (ISC) titled 'ISC Stormcast For Friday, September 11th, 2026'. It provides general information about the ISC's activities and resources but does not contain any specific security threat, vulnerability, or incident details.

LowNews
Join the discussion

CVE-2026-88914 is a moderate severity vulnerability in the GStreamer gst-plugins-good isomp4 plugin used in Red Hat Enterprise Linux 10. It involves an integer overflow in 32-bit unsigned arithmetic when processing specially crafted MP4 or MOV files containing CEA-608 closed-caption data. This overflow bypasses a bounds check, leading to an out-of-bounds heap read of up to 244 bytes, which can cause information disclosure or application crash. Exploitation requires user interaction by opening a malicious media file. No code execution is possible from this flaw. Red Hat is still analyzing affected products and currently has no mitigation that meets their standards.

Join the discussion

CVE-2026-89092 is a medium severity vulnerability in the GNU C Library (glibc) affecting versions from 2.3.4 up to but not including 2.45. It involves a stack overflow in the nscd service when a malicious DNS server returns an excessively large DNS response. This can cause nscd to crash, leading to degraded DNS resolution performance. Exploitation requires nscd to be enabled and configured to use an untrusted DNS server capable of sending large DNS records. The vulnerability does not cause denial of service but may corrupt nscd caches before crashing. The nscd service typically runs isolated with limited privileges, reducing risk of further compromise.

Join the discussion

CVE-2026-84941 is an information disclosure vulnerability in the SAML Single Sign-On (SSO) functionality of TP-Link Omada Software Controller for Windows. It affects versions 0 and all versions from 0 up to but not including 6.2.14.11. The flaw arises from insufficient validation of user-supplied SAML metadata, allowing an authenticated user with SAML configuration privileges to access sensitive information. The vulnerability has a CVSS 4.0 base score of 6.9, indicating medium severity. No official patch or remediation details are provided in the available data.

Join the discussion

A security researcher discovered an authentication bypass vulnerability in a YCombinator startup's platform that allowed unauthorized access to patient information, including personally identifiable information (PII) and protected health information (PHI). The vulnerability exposed API keys and tenant data behind an authentication guard. Attempts to responsibly disclose the issue to the startup's CEO were met with dismissal and blocking of the researcher. No patch or remediation information is provided.

Join the discussion

CVE-2026-17176 is an OS command injection vulnerability in the TDDP module of TP-Link Deco BE11000 V2. An adjacent network attacker can exploit this flaw by sending a crafted UDP packet to execute arbitrary commands with root privileges. Successful exploitation can lead to full device compromise, including unauthorized command execution and loss of confidentiality, integrity, and availability.

Join the discussion

CVE-2026-16174 is an integer overflow vulnerability in Netskope Endpoint DLP running on Windows. Exploitation requires the EPDLP module enabled and Memory Integrity disabled. A crafted message to the EPDLP process port can trigger memory corruption. This may lead to denial-of-service, arbitrary code execution, or privilege escalation locally. The vulnerability affects versions prior to 141.0. It has a high severity with a CVSS score of 8.7.

Join the discussion

CVE-2026-16172 is an out-of-bounds heap read vulnerability in the Netskope Endpoint DLP (EPDLP) service. A local standard user can send a specially crafted message that bypasses bounds checking, potentially causing the kernel driver handler to crash. Exploitation may disrupt DLP enforcement temporarily and could disclose per-boot memory layout information to unauthorized users. The vulnerability affects versions prior to 141.0. The CVSS 4.0 score rates this as medium severity.

Join the discussion

Showing 1 to 10 of 129604 results

Filters:Package: pkg:generic/p11-kit
Page 1 of 12961
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses