Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
0 An authenticated remote attacker with specific permissions can read or write files on the platform filesystem beyond the intended scope through specially crafted requests and/or crafted file uploads to the Software Management Studio Software Repository. Join the discussion | CVE Database V5 | 10/06/2026, 19:38:23 UTC Added: 10/06/2026, 19:49:45 UTC |
0 CVE-2026-101154 is a path traversal vulnerability in Arista Networks CloudVision Portal that allows an authenticated remote attacker with specific permissions to read or write files outside the intended directory scope. This occurs through specially crafted requests or file uploads targeting the Network Provisioning Image Repository. The vulnerability affects multiple versions of CloudVision Portal from 2018.1.0 through 2026.2.0. It has a high severity score of 7.2 and impacts confidentiality, integrity, and availability of the system. Join the discussion | CVE Database V5 | 10/06/2026, 19:38:22 UTC Added: 10/06/2026, 19:49:45 UTC |
0 On affected versions of CloudVision Portal (on-premises) or CloudVision Sensor, a path traversal vulnerability exists. An authenticated user with sufficient high privileges could exploit this to extract unintended data from the Sensor. Join the discussion | CVE Database V5 | 10/06/2026, 19:38:07 UTC Added: 10/06/2026, 19:49:50 UTC |
0 Insufficient validation in the Single Sign-On (SSO) login flow could allow a remote, unauthenticated attacker to craft a URL that, when clicked by a user, causes the identity provider (IdP) to deliver authentication material to an attacker-controlled URL instead of to CloudVision. Join the discussion | CVE Database V5 | 10/06/2026, 19:37:53 UTC Added: 10/06/2026, 19:49:50 UTC |
0 CVE-2026-101151 is an open redirect vulnerability in Arista Networks CloudVision Portal. It arises from insufficient validation of URLs in the login flow, allowing a remote unauthenticated attacker to craft a URL that redirects users to arbitrary external sites after authentication. This could potentially be used in phishing or social engineering attacks. The vulnerability has a medium severity with a CVSS score of 4.3. Join the discussion | CVE Database V5 | 10/06/2026, 19:37:53 UTC Added: 10/06/2026, 19:49:50 UTC |
0 CVE-2026-101150 is a server-side request forgery (SSRF) vulnerability in Arista Networks CloudVision Portal. It arises from insufficient validation of OIDC bearer token configuration, allowing a user with specific high privileges to direct requests to arbitrary destinations. The vulnerability affects multiple versions of CloudVision Portal, with a medium severity rating and a CVSS score of 4.1. There is no indication of known exploits in the wild. No patch or remediation information is provided in the available data. Join the discussion | CVE Database V5 | 10/06/2026, 19:37:25 UTC Added: 10/06/2026, 19:49:50 UTC |
0 CVE-2026-101149 is a server-side request forgery (SSRF) vulnerability in Arista Networks CloudVision Portal. It arises from insufficient validation of the OpenID Connect (OIDC) single sign-on (SSO) provider configuration. A user with specific high privileges could exploit this flaw to direct requests to arbitrary destinations. The vulnerability has a medium severity with a CVSS score of 4.1. It affects multiple versions of CloudVision Portal, including versions from 2020.3.0 up to 2026.1.2 and version 2026.2.0. No known exploits are reported in the wild. No patch or remediation details are provided in the available data. Join the discussion | CVE Database V5 | 10/06/2026, 19:37:25 UTC Added: 10/06/2026, 19:49:50 UTC |
A missing input validation vulnerability in the Fileserver upload API allows an authenticated attacker with file upload privileges to execute stored cross-site scripting (XSS). Successful exploitation could enable the attacker to hijack another CloudVision user's web session, potentially granting full access to their account and administrative permissions. Join the discussion | CVE Database V5 | 10/06/2026, 19:36:51 UTC Added: 10/06/2026, 19:49:52 UTC |
Showing 1 to 8 of 8 results