Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
0 Evolver is a GEP-powered self-evolving engine for AI agents. Prior to version 1.69.3, a prototype pollution vulnerability in the mailbox store module allows attackers to modify the behavior of all JavaScript objects by injecting malicious properties into Object.prototype. The vulnerability exists in the _applyUpdate() and _updateRecord() functions which use Object.assign() to merge user-controlled data without filtering dangerous keys like __proto__, constructor, or prototype. This issue has been patched in version 1.69.3. Join the discussion | CVE Database V5 | 05/04/2026, 16:50:15 UTC Added: 05/04/2026, 17:06:30 UTC |
0 CVE-2026-42076 is a critical OS command injection vulnerability in the EvoMap evolver product prior to version 1.69.3. The vulnerability exists in the _extractLLM() function, which constructs a shell command using unsanitized input and executes it via execSync(). This allows remote attackers to execute arbitrary shell commands on the server by injecting shell metacharacters through the corpus parameter. The issue has been addressed in version 1.69.3. The CVSS score is 9.8, indicating a critical severity with high impact on confidentiality, integrity, and availability. Join the discussion | CVE Database V5 | 05/04/2026, 16:48:51 UTC Added: 05/04/2026, 17:06:30 UTC |
0 Evolver is a GEP-powered self-evolving engine for AI agents. Prior to version 1.69.3, a path traversal vulnerability in the skill download (fetch) command allows attackers to write files to arbitrary locations on the filesystem. The --out= flag accepts user-provided paths without validation, enabling directory traversal attacks that can overwrite critical system files or create files in sensitive location. This issue has been patched in version 1.69.3. Join the discussion | CVE Database V5 | 05/04/2026, 16:47:23 UTC Added: 05/04/2026, 17:06:30 UTC |
Showing 1 to 3 of 3 results