Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
A critical deserialization vulnerability exists in elixir-grpc grpc versions starting from 0.4.0 before 1.0.0. The vulnerability arises from unsafe use of :erlang.binary_to_term/1 without safety options or size/type checks, allowing unauthenticated attackers to send crafted payloads that can exhaust the atom table and crash the BEAM VM or execute arbitrary code remotely. Join the discussion | CVE Database V5 | 06/15/2026, 21:56:15 UTC Added: 06/15/2026, 22:31:25 UTC |
0 A high severity vulnerability in elixir-grpc grpc (versions from 0.4.0 before 1.0.0) allows unauthenticated remote attackers to cause a denial of service via a gzip decompression bomb. The issue arises because the grpc gzip decompressor calls :zlib.gunzip/1 directly on attacker-controlled data without limiting decompressed size or checking compression ratio, leading to excessive memory allocation and potential out-of-memory crashes. Join the discussion | CVE Database V5 | 06/15/2026, 21:55:33 UTC Added: 06/15/2026, 22:31:25 UTC |
0 CVE-2026-48599 is an authorization bypass vulnerability in elixir-grpc grpc versions starting from 0.8.0 before 1.0.0. It allows authenticated attackers to override path-bound fields by supplying conflicting values via query strings or request bodies, causing handlers relying on these fields for authorization or ownership checks to be bypassed. Join the discussion | CVE Database V5 | 06/15/2026, 21:55:28 UTC Added: 06/15/2026, 22:31:25 UTC |
0 CVE-2026-48854 is a high-severity vulnerability in elixir-grpc grpc versions starting from 0.3.1 before 1.0.0. It allows unauthenticated attackers to exhaust server memory and crash the BEAM node by sending a large or slow-trickle unary request body. The vulnerability arises because the server accumulates incoming request chunks into a single binary without any size limit and uses an infinite timeout when the grpc-timeout header is omitted, enabling indefinite memory growth. Join the discussion | CVE Database V5 | 06/15/2026, 21:55:23 UTC Added: 06/15/2026, 22:31:25 UTC |
Showing 1 to 4 of 4 results