Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

CVE-2026-19752: Server-Side Request Forgery in EnzoVezzaro mcp-dominican-layerCVE-2026-19752
0

CVE-2026-19752 is a server-side request forgery (SSRF) vulnerability in the EnzoVezzaro mcp-dominican-layer project affecting the parse-pdf function in src/index.ts. The vulnerability allows remote attackers to manipulate the pdfUrl argument to initiate SSRF attacks. The issue affects versions up to commit 39dd373786712650097ad31db27d5c477c8f9c82. The vulnerability has a medium severity with a CVSS score of 5.3. The project has been informed but has not yet responded or issued a fix. Exploit code has been publicly disclosed but there are no known exploits in the wild at this time.

Join the discussion
CVE-2026-19751: Server-Side Request Forgery in EnzoVezzaro mcp-dominican-layerCVE-2026-19751
0

CVE-2026-19751 is a server-side request forgery (SSRF) vulnerability in the EnzoVezzaro mcp-dominican-layer product. The flaw exists in the axios.get function call within the src/index.ts file of the parse-csv component, where manipulation of the csvUrl argument can lead to SSRF. The vulnerability can be exploited remotely, and proof-of-concept exploit code has been published. The product uses a rolling release strategy, so specific affected or fixed versions are not provided. The vendor has been informed but has not yet responded or issued a fix.

Join the discussion

Showing 1 to 2 of 2 results

Filters:Package: pkg:github/enzovezzaro/mcp-dominican-layer
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses