Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
0 Netcore NR255-V version 1.5.130703 contains a stored cross-site scripting (XSS) vulnerability in its L7 content management pages. The vulnerability arises from the use of eval() sinks in call board text and policy group handling components, allowing attackers to inject persistent malicious scripts. These scripts execute in the context of other users viewing the affected content, potentially leading to unauthorized actions or data exposure. The CVSS 4.0 base score is 5.1, indicating a medium severity level. Join the discussion | CVE Database V5 | 09/16/2026, 00:31:32 UTC Added: 09/15/2026, 22:02:23 UTC |
Netcore NR255-V version 1.5.130703 has a vulnerability that allows attackers to disclose sensitive information. Specifically, attackers can access certain CGI endpoints to retrieve stored IPsec pre-shared keys and RSA key material. This exposure could compromise VPN security. The vulnerability has a high severity rating with a CVSS score of 7.1. No patch or remediation information is provided in the available data. Join the discussion | CVE Database V5 | 09/16/2026, 00:31:32 UTC Added: 09/15/2026, 22:02:23 UTC |
0 CVE-2026-92255 is an out-of-bounds read vulnerability in Netcore NR255-V version 1.5.130703. The flaw exists in the filter_arp_put_file.cgi component due to improper use of a string handling API, which can lead to an unterminated buffer over-read. This may expose adjacent memory contents. The vulnerability has a medium severity with a CVSS score of 5.3. No patch or remediation information is provided. Join the discussion | CVE Database V5 | 09/16/2026, 00:31:32 UTC Added: 09/15/2026, 22:02:23 UTC |
0 Netcore NR255-V version 1.5.130703 contains a stored cross-site scripting (XSS) vulnerability in its web management interface. The flaw exists in the DHCP dynamic IP display and ARP bind list display components, where hostname fields are improperly neutralized. A local attacker on the LAN can inject malicious scripts into these hostname fields, which are later rendered by network_config.js and network_security.js, potentially leading to script execution in the administrator's browser. Join the discussion | CVE Database V5 | 09/16/2026, 00:31:31 UTC Added: 09/15/2026, 22:02:23 UTC |
0 Netcore NR255-V version 1.5.130703 contains a stored cross-site scripting (XSS) vulnerability in its DHCP static IP and IP ACL management web pages. This vulnerability allows attackers to inject persistent malicious scripts via specific CGI components, potentially compromising the web management interface for other users. The CVSS 4.0 base score is 5.1, indicating a medium severity level. Join the discussion | CVE Database V5 | 09/16/2026, 00:31:31 UTC Added: 09/15/2026, 22:02:23 UTC |
Netcore NR255-V version 1.5.130703 has a vulnerability that allows attackers to disclose sensitive VPN credentials. The flaw exists in specific components handling VPN user information, enabling unauthorized access to PPTP and L2TP VPN credentials. This vulnerability has a high severity rating with a CVSS score of 7.1. Join the discussion | CVE Database V5 | 09/16/2026, 00:31:30 UTC Added: 09/15/2026, 22:02:22 UTC |
0 Netcore NR255-V version 1.5.130703 has a null pointer dereference vulnerability in the route_policy_add.cgi component. This occurs when a request is sent without the required exit_port parameter, causing the device to dereference a null pointer and crash, leading to denial of service. Join the discussion | CVE Database V5 | 09/16/2026, 00:31:30 UTC Added: 09/15/2026, 22:02:22 UTC |
0 CVE-2026-76866 is a high-severity vulnerability in Netcore NR255-V firmware version 1.5.130703. It involves improper neutralization of argument delimiters in command lines constructed from unquoted user-supplied DDNS input, allowing command argument injection with root privileges. This flaw exists in the DDNSset_cgi.c and ddns_Proc.c components. Exploitation could enable attackers to execute arbitrary commands as root on the affected device. Join the discussion | CVE Database V5 | 09/16/2026, 00:31:30 UTC Added: 09/15/2026, 22:02:22 UTC |
0 Netcore NR255-V version 1.5.130703 contains a null pointer dereference vulnerability in specific QoS setter CGI handlers. This flaw arises from unchecked results of the atoi() function, allowing an attacker to cause a denial of service by supplying crafted input. The vulnerability has a medium severity rating with a CVSS score of 6.9. Join the discussion | CVE Database V5 | 09/16/2026, 00:31:30 UTC Added: 09/15/2026, 22:02:22 UTC |
0 NR255-V version 1.5.130703 fails to sanitize QoS rule names before they are parsed via eval() in qos_xianz_add_cgi, qos_xianz_show_cgi, qos_filter_add_cgi, and qos_filter_show_cgi handlers. An attacker can inject persistent script code through crafted QoS rule name input that executes when the stored data is later processed by the affected handlers.' Join the discussion | CVE Database V5 | 09/16/2026, 00:31:30 UTC Added: 09/15/2026, 22:02:22 UTC |
Showing 1 to 10 of 19 results