Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

CVE-2026-71958: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') in D-Link Corporation DWR-M961CVE-2026-71958
0

D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_202602110044 contain a buffer overflow vulnerability in the quicksetup.cgi interface. A remote attacker can write overly long strings to the test4, ssid2, and username fields and execute arbitrary commands by crafting a specific payload, or cause the device to crash.

Join the discussion
CVE-2026-71957: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') in D-Link Corporation DWR-M961CVE-2026-71957
0

D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_202602110044 contain a buffer overflow vulnerability in the app.cgi interface. A remote attacker can write an overly long string to the netAcc.addlist[].name field and execute arbitrary commands by crafting a specific payload, or cause the device to crash.

Join the discussion
CVE-2026-71956: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in D-Link Corporation DWR-M961CVE-2026-71956
0

D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_202602110044 contain a command injection vulnerability in the app.cgi interface. A remote attacker can inject arbitrary malicious commands into the netDig.ping.dst field, resulting in command execution with root privileges.

Join the discussion
Radare2: Heap-buffer-overflow in load_buffer
0

A heap-buffer-overflow vulnerability has been identified in the load_buffer function of Radare2. This issue was reported by OSS-Fuzz and involves an out-of-bounds read of 8 bytes. The vulnerability affects multiple specific versions of Radare2 from 5.6.8 through 6.2.0. No CVSS score or detailed impact analysis is provided, and there are no known exploits in the wild. No patch or official remediation information is available in the provided data.

Join the discussion
A vulnerability was detected in aaronsb memory-graph up to 5cfd2382778837b9f6399080956eee670d00452c. (CVE-2026-19285)CVE-2026-19285
0

A path traversal vulnerability exists in the aaronsb memory-graph project affecting functions in src/tools/memoryTools.ts. The issue requires local access to exploit and impacts confidentiality, integrity, and availability at a low severity level. The project uses a rolling release model, so no specific affected or fixed versions are identified. The vendor has been informed but has not yet responded or issued a fix.

Join the discussion
A security vulnerability has been detected in MauricioMilano coder-api up to 1.1.0. (CVE-2026-19284)CVE-2026-19284
0

A command injection vulnerability exists in the createProject function of the src/core/projects.ts file in MauricioMilano coder-api versions up to 1.1.0. The vulnerability requires local access to exploit and can lead to limited confidentiality, integrity, and availability impacts. The issue was reported but the project has not yet responded with a fix.

Join the discussion
A vulnerability has been found in astralisone rive-mcp-server-core up to db1d0cc4cd52589116360428b7504fd0ca748b3e. (CVE-2026-19288)CVE-2026-19288
0

CVE-2026-19288 is a local path traversal vulnerability in the astralisone rive-mcp-server-core component importRiveFile Flow. It involves manipulation of the argument libraryId in the file importRiveFile.ts. The vulnerability affects versions up to commit db1d0cc4cd52589116360428b7504fd0ca748b3e. The project uses a rolling release model, so specific affected versions are not available. No patch or vendor response has been reported yet. The CVSS 3.1 base score is 5.3, indicating a low severity issue.

Join the discussion
CVE-2026-71955: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in D-Link Corporation DWR-M961CVE-2026-71955
0

D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_202602110044 contain a command injection vulnerability in the /boafrm/formWsc interface. A remote attacker can inject arbitrary malicious commands into the localPin, targetAPSsid, peerPin, and peerRptPin fields, resulting in command execution with root privileges.

Join the discussion
CVE-2026-71954: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in D-Link Corporation DWR-M961CVE-2026-71954
0

D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formL2tpv3ConfigSetup interface. A remote attacker can inject arbitrary malicious commands into the tunnelid and sessionid fields, resulting in command execution with root privileges.

Join the discussion
CVE-2026-71953: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in D-Link Corporation DWR-M961CVE-2026-71953
0

D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formNtp interface. A remote attacker can inject arbitrary malicious commands into the ntpServerIp1 field, resulting in command execution with root privileges.

Join the discussion

Showing 1 to 10 of 23459 results

Filters:Package: pkg:generic/radare2
Page 1 of 2346
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses