Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
0 A flaw was found in CRI-O's `bind_mount_prefix` handling. When configured with a non-empty `bind_mount_prefix`, a malicious container or local attacker could use a Container Runtime Interface (CRI) hostPath containing an intermediate absolute symlink. This could cause the bind mount source to resolve outside the intended prefixed root, potentially leading to unauthorized access to files or privilege escalation on the host system. Join the discussion | CVE Database V5 | 10/06/2026, 19:24:30 UTC Added: 10/06/2026, 19:34:38 UTC |
0 A vulnerability in CRI-O checkpoint restore allows a user who can create a pod from a malicious checkpointed container to bypass the destination Kubernetes security context. The restored process may retain credentials, Linux capabilities, no_new_privs, and seccomp state from the checkpoint instead of enforcing the destination configuration. This can allow execution with elevated privileges across the container security boundary. Affected upstream supported versions are CRI-O 1.34 and later. Downstream Red Hat products are affected from OCP 4.17 onward. Fixes have been applied to supported branches but are not yet released. Exploitation requires permission to create a pod from a malicious checkpoint image and checkpoint restore functionality to be available. Join the discussion | CVE Database V5 | 09/21/2026, 09:49:49 UTC Added: 09/21/2026, 10:02:05 UTC |
CVE-2026-17113 is a vulnerability in CRI-O's handling of container environment variables during container creation. When a CreateContainer request provides a nil environment variable field, CRI-O uses the OCI image's environment variables without validating their format. If an environment variable lacks an '=' character, CRI-O attempts to access a non-existent array element, causing a runtime panic that crashes the crio daemon and disrupts container runtime services on the node until restarted. Join the discussion | CVE Database V5 | 08/24/2026, 21:22:49 UTC Added: 08/24/2026, 21:37:47 UTC |
0 A flaw was found in cri-o. A malicious container can create a symbolic link to arbitrary files on the host via directory traversal (“../“). This flaw allows the container to read and write to arbitrary files on the host system. Join the discussion | CVE Database V5 | 06/12/2024, 08:51:43 UTC Added: 11/20/2025, 07:29:55 UTC |
0 A flaw was found in cri-o, where an arbitrary systemd property can be injected via a Pod annotation. Any user who can create a pod with an arbitrary annotation may perform an arbitrary action on the host system. Join the discussion | CVE Database V5 | 04/26/2024, 03:12:38 UTC Added: 11/20/2025, 07:29:54 UTC |
Showing 1 to 5 of 5 results