Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
0 CVE-2026-108864 is an authorization bypass vulnerability in iFlytek Astron Agent versions up to 1.1.2. It allows authenticated applications to resume workflows of other applications by supplying their event_id to the resume endpoint. This breaks cross-tenant isolation by enabling attackers to inject resume content and read continuation output streams of victim workflows. The vulnerability has a low CVSS score of 2.3 and affects cloud-hosted services. Join the discussion | CVE Database V5 | 10/11/2026, 13:26:10 UTC Added: 10/11/2026, 13:49:07 UTC |
0 CVE-2026-108263 is a critical vulnerability in iflytek's astron-agent prior to version 1.1.2. It involves improper neutralization of directives in dynamically evaluated code, allowing an authenticated low-privilege tenant to execute arbitrary code as root within the core-workflow container. This can lead to bypassing tenant isolation, unauthorized access to other tenants' data, and disruption of shared services. The issue is fixed in version 1.1.2. Join the discussion | CVE Database V5 | 10/09/2026, 20:47:38 UTC Added: 10/09/2026, 21:04:01 UTC |
A security vulnerability has been detected in iFlytek astron-agent up to 1.0.6. Affected by this vulnerability is the function UrlCheckTool.checkUrl of the component debugToolV2 API endpoint. The manipulation of the argument endPoint leads to server-side request forgery. The attack can be initiated remotely. Upgrading to version reward-1575 addresses this issue. The identifier of the patch is 45ee5fb647e9894e73b0d7720fa94a66e4540bbb. The affected component should be upgraded. Join the discussion | CVE Database V5 | 09/23/2026, 02:15:20 UTC Added: 09/23/2026, 02:33:12 UTC |
0 A weakness has been identified in iFlytek astron-agent up to 1.0.7. Affected is an unknown function of the file console/backend/commons/src/main/resources/mapper/ChatBotMarketMapper.xml of the component getBotList API endpoint. Executing a manipulation of the argument sortDirection can lead to sql injection. It is possible to launch the attack remotely. Upgrading to version reward-1575 is able to address this issue. This patch is called 6702be70ae802b1048f5fbec91e690e7b71a4165. You should upgrade the affected component. Join the discussion | CVE Database V5 | 09/23/2026, 02:00:12 UTC Added: 09/23/2026, 02:33:12 UTC |
Showing 1 to 4 of 4 results