Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
CVE-2026-20148 is a medium severity vulnerability in Cisco Identity Services Engine Software that allows an authenticated attacker with administrative credentials to perform path traversal attacks. This flaw enables reading arbitrary files on the underlying operating system by sending crafted HTTP requests due to improper validation of user input. The vulnerability affects specific versions 3.1.0 through 3.5.0 of the software. There is no confirmed patch or official remediation guidance available at this time. Join the discussion | CVE Database V5 | 08/13/2026, 05:00:00 UTC Added: 04/15/2026, 16:16:56 UTC |
0 A vulnerability in the IP Access Restriction feature of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to bypass configured IP access restrictions and log in to the device from a disallowed IP address. This vulnerability is due to improper enforcement of access controls that are configured using the IP Access Restriction feature. An attacker could exploit this vulnerability by logging in to the API from an unauthorized source IP address. A successful exploit could allow the attacker to gain access to the targeted device from an IP address that should have been restricted. To exploit this vulnerability, the attacker must have valid administrative credentials. Join the discussion | CVE Database V5 | 07/16/2025, 16:16:56 UTC Added: 07/16/2025, 16:31:12 UTC |
A vulnerability in a specific API of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to execute arbitrary code on the underlying operating system as root. This vulnerability is due to insufficient validation of user-supplied input. An attacker with valid credentials could exploit this vulnerability by submitting a crafted API request. A successful exploit could allow the attacker to execute commands as the root user. To exploit this vulnerability, the attacker must have valid high-privileged credentials. Join the discussion | CVE Database V5 | 07/16/2025, 16:16:37 UTC Added: 07/16/2025, 16:31:12 UTC |
A vulnerability in a specific API of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to execute arbitrary code on the underlying operating system as root. The attacker does not require any valid credentials to exploit this vulnerability. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by submitting a crafted API request. A successful exploit could allow the attacker to obtain root privileges on an affected device. Join the discussion | CVE Database V5 | 06/25/2025, 16:11:42 UTC Added: 06/25/2025, 16:21:56 UTC |
Showing 1 to 4 of 4 results