Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
0 CVE-2026-88816 is a high-severity vulnerability in Perl's DBI module versions before 1.654. It involves a type confusion issue where numeric values are incorrectly treated as strings in the FetchHashKeyName attribute. This leads to invalid pointer dereferencing and causes a segmentation fault when fetchrow_hashref is called with a numeric FetchHashKeyName. The vulnerability can be triggered by setting FetchHashKeyName to an integer or floating-point value and then fetching a row hash reference. Join the discussion | CVE Database V5 | 09/28/2026, 16:04:40 UTC Added: 09/28/2026, 16:33:16 UTC |
0 CVE-2026-88815 is a type confusion vulnerability in Perl's DBI module versions before 1.654. It occurs when numeric values are incorrectly treated as strings during SQL type casting, leading to a segmentation fault. This flaw arises because the function sql_type_cast_svpv passes a string pointer without proper stringification, causing invalid memory access. The vulnerability can be triggered by calling sql_type_cast with a numeric value and SQL_NUMERIC type. Join the discussion | CVE Database V5 | 09/28/2026, 16:04:22 UTC Added: 09/28/2026, 16:33:16 UTC |
0 DBI versions before 1.653 for Perl load arbitrary modules via unvalidated dbm_type and dbm_mldbm attributes in DBD::DBM. DBD::DBM passes the dbm_type and dbm_mldbm connect attributes to require without checking that the value names a module. require treats a path-shaped string as a literal filename and does not consult @INC, so the attribute chooses the file that Perl loads and runs. The MLDBM::Serializer:: prefix that DBD::DBM prepends to dbm_mldbm is not a boundary: only the :: separators are rewritten to /, so a value containing / traverses out of the serializer directory. The value is also assigned to $MLDBM::Serializer, which MLDBM requires the same way when it ties the table. A caller that lets an untrusted party influence either attribute, for example through a DSN fragment or a parameter that selects a storage backend, runs the file-scope code of whatever module the value names. For example, my $dsn = "dbi:DBM:f_dir=/var/db;dbm_type=../../Untrusted.pm" my $dbh = DBI->connect( $dsn ); Note that DBD::Gofer forwards connect attributes to the server side, and DBI::ProxyServer checks only that a DSN starts with a driver prefix. Join the discussion | CVE Database V5 | 09/19/2026, 10:45:10 UTC Added: 09/19/2026, 11:02:06 UTC |
0 CVE-2026-73193 is a critical integer overflow vulnerability in DBI for Perl versions before 1.652 on 32-bit Perl builds. It allows a heap out-of-bounds write due to an integer wraparound in the output buffer size calculation during statement preprocessing. This can lead to memory corruption when processing very large input statements. 64-bit Perl builds are not affected. The vulnerability has a CVSS score of 9.8, indicating high severity. Join the discussion | CVE Database V5 | 09/11/2026, 00:00:00 UTC Added: 08/15/2026, 12:26:39 UTC |
DBI versions before 1.652 for Perl allow a heap out-of-bounds write via an unvalidated numeric placeholder that sets the binder counter in preparse. preparse reserves seven output bytes per input byte, the width of the longest ':p99999' expansion. The ':N' branch parses the number with `atoi(src)` and assigns it to the binder counter with no range check, so a statement containing ':2147483648' leaves the counter negative (-2147483648 with glibc, where atoi wraps). Each following '?' then expands through `sprintf(start, ":p%d", idx++)` to ':p-2147483648', 14 bytes with the terminating NUL where the buffer budgets 7. The placeholder limit added in 1.650 tests the counter against 99,999, which a negative counter passes. Any caller that preparses an untrusted statement into ':pN' style placeholders gets a heap out-of-bounds write that grows with the number of '?' marks following the poisoned placeholder. The '?' and '%s' return styles compare the parsed number against the expected sequence and error out, and are unaffected. Join the discussion | CVE Database V5 | 08/15/2026, 12:09:22 UTC Added: 08/15/2026, 12:26:39 UTC |
DBI::SQL::Nano versions from 1.42 before 1.651 for Perl have inverted <= and >= SQL operators on text. DBI::SQL::Nano, DBI's built-in mini-SQL engine, evaluated WHERE predicates incorrectly in some cases. In the non-numeric string branch of the is_matched method, <= was evaluated using Perl's ge operator, and >= was evaluated using Perl's le operator. SQL::Nano is the fallback query engine for DBI's file-backed drivers (DBD::File, DBD::DBM, CSV-style drivers) whenever SQL::Statement is not installed, and is forced whenever DBI_SQL_NANO=1. Queries over such tables use these predicates directly. The impact depends on the context. Where an application relies on a WHERE clause to filter file-backed data for policy or authorization, an inverted <=/>= comparison silently returns the wrong rows. Join the discussion | CVE Database V5 | 07/17/2026, 00:00:00 UTC Added: 07/14/2026, 10:03:05 UTC |
0 DBI versions before 1.651 for Perl do not enforce statement handle consistency with the row. When the statement handle had no fields but the source row was non-empty, the internal row-buffer helper would read from a negative array index. This could be triggered by a caller supplying inconsistent metadata and rows to the prepare method. Join the discussion | CVE Database V5 | 07/14/2026, 15:35:00 UTC Added: 07/14/2026, 15:48:13 UTC |
0 DBI::ProfileData versions before 1.651 for Perl do not limit the path index. The path index column of profile dump files is used to allocate an array of data for the parser. An unbounded value allows an attacker to specify a large index and consume available memory. Join the discussion | CVE Database V5 | 07/14/2026, 15:34:35 UTC Added: 07/14/2026, 15:48:13 UTC |
0 DBD::File versions before 1.651 for Perl do not ensure the table file is not a symlink to an untrusted location. The complete_table_name method builds the absolute table file path without checking whether the file is a symbolic link. A link inside the data directory can point to a table file at any path outside of the configured f_dir and f_dir_search directories. Callers of file-based drivers can read or write files outside of the data directory. Join the discussion | CVE Database V5 | 07/14/2026, 15:34:01 UTC Added: 07/14/2026, 15:48:11 UTC |
0 DBI versions before 1.650 for Perl read one byte out-of-bounds in preparse when deleting an initial SQL comment. The preparse method normalises SQL and removes comments. When the SQL starts with a comment line, the deletion of that line during normalisation led to an out-of-bounds read by one byte. The result is a fault on memory-hardened builds and nondeterministic newline retention on normal builds. Join the discussion | CVE Database V5 | 07/07/2026, 22:05:45 UTC Added: 07/07/2026, 22:44:08 UTC |
Showing 1 to 10 of 14 results