Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
CVE-2026-62357 is an integer overflow vulnerability in dragonflydb's dragonfly prior to version 1.40.0. The flaw occurs in CMS.INITBYDIM and CMS.INITBYPROB functions, where dimensions can overflow when calculating buffer size, leading to undersized allocation. This allows an unauthenticated remote attacker to corrupt or disclose adjacent heap memory and potentially crash the server. The issue is fixed in version 1.40.0. Join the discussion | CVE Database V5 | 08/18/2026, 15:18:52 UTC Added: 08/18/2026, 15:34:54 UTC |
Dragonfly is an in-memory data store built for modern application workloads. Prior to 1.39.0, a crafted RESTORE payload triggers an out-of-bounds read in DragonflyDB's listpack collection loaders, crashing the entire server process (SIGSEGV). Because DragonflyDB requires no authentication by default and RESTORE is a normal keyspace command, an unauthenticated remote attacker can crash the server with a single ~24-byte command — a remote, repeatable denial of service. This vulnerability is fixed in 1.39.0. Join the discussion | CVE Database V5 | 06/26/2026, 16:42:15 UTC Added: 06/26/2026, 17:21:53 UTC |
0 Dragonfly is an in-memory data store built for modern application workloads. Prior to 1.39.9, Dragonfly has a RESP Protocol Injection via Lua redis.error_reply() in EvalSerializer. An authenticated user can inject arbitrary RESP messages into the connection's response stream, potentially causing response desynchronization in connection-pool clients. This vulnerability is fixed in 1.39.9. Join the discussion | CVE Database V5 | 06/26/2026, 16:39:27 UTC Added: 06/26/2026, 17:21:53 UTC |
0 Dragonfly is an open source P2P-based file distribution and image acceleration system. In versions 2.4.1-rc.0 and below, the Job API endpoints (/api/v1/jobs) lack JWT authentication middleware and RBAC authorization checks in the routing configuration. This allows any unauthenticated user with access to the Manager API to view, update and delete jobs. The issue is fixed in version 2.4.1-rc.1. Join the discussion | CVE Database V5 | 01/22/2026, 22:20:20 UTC Added: 01/22/2026, 22:35:56 UTC |
Integer Overflow or Wraparound vulnerability in dragonflydb dragonfly (src/redis/lua/struct modules). This vulnerability is associated with program files lua_struct.C. This issue affects dragonfly: 1.30.1, 1.30.0, 1.28.18. Join the discussion | CVE Database V5 | 06/23/2025, 09:27:18 UTC Added: 06/23/2025, 09:49:27 UTC |
Showing 1 to 5 of 5 results