Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
0 CVE-2026-96258 is a cross-site scripting (XSS) vulnerability in onSite internet GmbH Auktion NG Auktionssoftware affecting the /forgotpasswd.html page's email parameter. This vulnerability allows remote attackers to inject malicious scripts via the email argument in the public password reset endpoint. The vulnerability is present in versions up to 20260722. The vendor was contacted but did not respond, and no patch or remediation information is currently available. The vulnerability has a medium severity with a CVSS score of 5.3. Exploit details have been publicly disclosed but no known active exploitation in the wild has been reported. Join the discussion | CVE Database V5 | 09/23/2026, 03:15:08 UTC Added: 09/23/2026, 03:33:19 UTC |
CVE-2026-96257 is a critical stack-based buffer overflow vulnerability in Fast FAC1203R Gigabit Edition version 2.0.4. The flaw exists in the copy_msg_element function of the Device Discovery Service component and can be exploited remotely without authentication. Exploit code has been published, but no vendor response or patch is currently available. Join the discussion | CVE Database V5 | 09/23/2026, 03:00:10 UTC Added: 09/23/2026, 03:18:28 UTC |
0 CVE-2026-95958 is an integer underflow vulnerability in JusticeRage Manalyze version 1.0.0. The flaw exists in the PE::_parse_relocations function within the PE Parser component, where manipulation of the BlockSize argument can trigger the underflow. Exploitation requires local access. A patch identified by commit c372b6bbca9d8c63812be50596fefa4a79c65fd0 is recommended to remediate this issue. Join the discussion | CVE Database V5 | 09/23/2026, 02:45:14 UTC Added: 09/23/2026, 03:03:27 UTC |
This entry is a daily update from the SANS Internet Storm Center (ISC) titled 'ISC Stormcast For Wednesday, September 23rd, 2026.' It provides general security news and information but does not describe any specific security threat or vulnerability. LowNews Join the discussion | SANS ISC Handlers Diary | 09/23/2026, 02:40:13 UTC Added: 09/23/2026, 02:47:48 UTC |
0 CVE-2026-95957 is a cross-site scripting (XSS) vulnerability in SourceCodester Smart Attendance System with QR Code Scanner version 1.0. The flaw exists in the prepend function of the student_signup.php file within the Self-Registration component. An attacker can manipulate the full_name argument to inject malicious scripts. Remote exploitation is possible, and a public exploit is available. The vulnerability has a medium severity rating with a CVSS score of 5.3. Join the discussion | CVE Database V5 | 09/23/2026, 02:30:16 UTC Added: 09/23/2026, 02:48:25 UTC |
0 CVE-2026-91777 is a high-severity vulnerability in FasterXML jackson-databind affecting versions from 2.5.0 through 3.2.2 in specified ranges. It involves uncontrolled resource consumption due to a quadratic CPU workload during deserialization of JSON documents with forward-reference completion for @JsonIdentityInfo object IDs. This occurs when unresolved object-ID references are defined in reverse order, causing excessive identity comparisons. Exploitation requires deserialization of attacker-controlled JSON into identity-enabled collections or maps. Join the discussion | CVE Database V5 | 09/23/2026, 02:21:48 UTC Added: 09/23/2026, 02:33:12 UTC |
0 CVE-2026-91776 is a high-severity vulnerability in FasterXML jackson-databind affecting versions from 2.0.0 through 3.2.2 in various ranges. It involves uncontrolled resource consumption due to caching of attacker-supplied unknown type IDs in the deserializer cache when name-based polymorphism with a fallback is enabled. This can lead to monotonic memory retention and potential denial of service. The vulnerability requires specific application configurations and long-lived ObjectMapper instances. A fix is available that stops caching fallback resolutions for unrecognized IDs and bounds the cache size. Join the discussion | CVE Database V5 | 09/23/2026, 02:17:50 UTC Added: 09/23/2026, 02:33:12 UTC |
CVE-2026-95930 is a server-side request forgery (SSRF) vulnerability in iFlytek astron-agent versions 1.0.0 through 1.0.6. The flaw exists in the UrlCheckTool.checkUrl function of the debugToolV2 API endpoint, where manipulation of the endPoint argument allows remote attackers to induce SSRF. This vulnerability is addressed by upgrading to version reward-1575. Join the discussion | CVE Database V5 | 09/23/2026, 02:15:20 UTC Added: 09/23/2026, 02:33:12 UTC |
0 CVE-2026-89425 is a high-severity vulnerability in FasterXML jackson-core affecting versions from 2.8.0 through 3.2.2 in various sub-ranges. The issue occurs in UTF8DataInputJsonParser._reportInvalidToken(), which builds error messages by appending characters to a StringBuilder without an upper bound, leading to excessive memory consumption. This can cause OutOfMemoryError in the JVM when processing large malformed tokens via the DataInput parsing path. The vulnerability does not affect releases before 2.8.0 and is not mitigated by existing StreamReadConstraints settings. No official patch information is provided in the input data. Join the discussion | CVE Database V5 | 09/23/2026, 02:06:10 UTC Added: 09/23/2026, 02:33:12 UTC |
0 CVE-2026-95929 is a medium severity SQL injection vulnerability in iFlytek astron-agent versions 1.0.0 through 1.0.7. The flaw exists in the getBotList API endpoint within the ChatBotMarketMapper.xml file, where manipulation of the sortDirection argument can lead to SQL injection. The vulnerability can be exploited remotely without user interaction. Upgrading to version reward-1575 addresses this issue. Join the discussion | CVE Database V5 | 09/23/2026, 02:00:12 UTC Added: 09/23/2026, 02:33:12 UTC |
Showing 1 to 10 of 137876 results