Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
stigmem versions before 0.9.0a2 and version 0.9.0 have an improper authorization vulnerability that allows unauthenticated access when authentication is disabled on non-loopback deployments. This enables attackers to perform read, write, and federation operations anonymously if nodes are exposed outside local development environments. Join the discussion | CVE Database V5 | 08/19/2026, 14:02:20 UTC Added: 08/19/2026, 14:24:00 UTC |
stigmem-node versions before 0.9.0a2 and version 0.9.0 have an improper certificate validation vulnerability. The software accepts federation peer key material during peer registration without requiring an out-of-band administrator fingerprint approval. This allows an attacker who can intercept or misdirect initial registration over the network to register a malicious peer and potentially access or tamper with federation traffic. The issue is fixed in version 0.9.0a2 by introducing a pending approval flow requiring administrator fingerprint verification. Join the discussion | CVE Database V5 | 08/19/2026, 14:02:19 UTC Added: 08/19/2026, 14:24:00 UTC |
stigmem-node versions before 0.9.0a2 allow disabling plugin signature enforcement with a single configuration flag, which can lead to loading and executing unsigned plugin code if plugin directories are writable by less-trusted users. This vulnerability enables arbitrary code execution. The issue is fixed in version 0.9.0a2 by requiring a second explicit acknowledgment to disable signature enforcement. Join the discussion | CVE Database V5 | 08/19/2026, 14:02:18 UTC Added: 08/19/2026, 14:24:00 UTC |
0 stigmem-node versions before 0.9.0a2 and version 0.9.0 contain an SQL injection vulnerability due to improper neutralization of special elements in SQL commands. The vulnerability arises because schema identifiers are interpolated into SQL strings without proper quoting, and these schema names can be influenced by operator-controlled input. The issue is fixed in version 0.9.0a2 by adding identifier quoting and validation. As a workaround, schema names should only be configured from trusted deployment configurations. Join the discussion | CVE Database V5 | 08/19/2026, 14:02:18 UTC Added: 08/19/2026, 14:24:00 UTC |
CVE-2026-76239 is a server-side request forgery (SSRF) vulnerability in eidetic-labs stigmem-node versions before 0.9.0a11. The flaw arises because the delivery_address parameter used when creating webhook subscriptions is not properly validated. Authenticated users can exploit this to make the server send HTTP POST requests to internal loopback and private network addresses, enabling blind SSRF attacks. Join the discussion | CVE Database V5 | 08/19/2026, 14:02:17 UTC Added: 08/19/2026, 14:24:00 UTC |
stigmem-node versions before 0.9.0a12 have an object level authorization vulnerability in the decay sweep endpoint. Authenticated users with write access to one tenant can perform decay operations that affect all tenants, leading to cross-tenant data expiration or information disclosure via dry runs. Join the discussion | CVE Database V5 | 08/19/2026, 14:02:16 UTC Added: 08/19/2026, 14:24:00 UTC |
0 stigmem-node versions before 0.9.0a12 contain an authorization bypass vulnerability affecting multi-tenant deployments using the stigmem-plugin-multi-tenant. This flaw allows a tenant administrator with write access to their own tenant to access and manipulate quarantined facts of other tenants via the /v1/quarantine endpoints. Single-tenant deployments are not affected. Join the discussion | CVE Database V5 | 08/19/2026, 14:02:15 UTC Added: 08/19/2026, 14:23:58 UTC |
0 stigmem-node versions before 0.9.0a12 contain a broken object level authorization (BOLA) vulnerability in the multi-tenant right-to-be-forgotten (RTBF) tombstone mechanism. This flaw allows deletion records to be incorrectly attributed across tenants, undermining data isolation and RTBF guarantees. The issue affects only multi-tenant deployments using the stigmem-plugin-multi-tenant. The vulnerability is fixed in version 0.9.0a12. Join the discussion | CVE Database V5 | 08/19/2026, 14:02:15 UTC Added: 08/19/2026, 14:23:58 UTC |
Showing 1 to 8 of 8 results