Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
0 CVE-2026-40343 is a medium severity vulnerability in free5GC's user data repository (UDR) component up to version 1.4.2. The flaw involves improper handling of errors in the POST handler for the /nudr-dr/v2/policy-data/subs-to-notify endpoint, where the service continues processing requests despite failures in request body retrieval or deserialization. This can lead to unintended creation of policy data notification subscriptions with invalid or incomplete input. No patch or official remediation is available at the time of publication. Join the discussion | CVE Database V5 | 04/21/2026, 23:47:33 UTC Added: 04/22/2026, 00:01:08 UTC |
0 CVE-2026-5661 is a medium severity vulnerability in Free5GC version 4.2.0 affecting the NGSetupRequest Handler component. It allows a remote attacker to cause a denial of service condition. The vulnerability can be exploited without authentication or user interaction. Although an exploit is publicly available, there are no confirmed reports of exploitation in the wild. No official patch or remediation guidance has been provided yet. Join the discussion | CVE Database V5 | 04/06/2026, 14:08:19 UTC Added: 04/06/2026, 14:30:30 UTC |
0 A vulnerability has been found in Free5GC 4.2.0. The affected element is an unknown function of the component aper. Such manipulation leads to type confusion. The attack may be launched remotely. This attack is characterized by high complexity. The exploitability is described as difficult. The exploit has been disclosed to the public and may be used. The name of the patch is 26205eb01705754b7b902ad6c4b613c96c881e29. It is best practice to apply a patch to resolve this issue. Join the discussion | CVE Database V5 | 04/02/2026, 17:00:19 UTC Added: 04/02/2026, 17:08:18 UTC |
0 CVE-2026-30653 is a high-severity vulnerability in Free5GC version 4.2.0 and earlier that allows a remote attacker to cause a denial of service (DoS) by exploiting the HandleAuthenticationFailure function in the AMF component. The flaw does not require authentication or user interaction and can be triggered remotely over the network. It impacts availability but does not affect confidentiality or integrity. No known exploits are currently reported in the wild. The vulnerability is classified under CWE-400, indicating a resource exhaustion issue. Organizations using Free5GC for 5G core network functions are at risk of service disruption. Mitigation involves applying patches once available or implementing network-level protections to limit exposure. Countries with significant 5G deployments using Free5GC are most likely to be affected. Join the discussion | CVE Database V5 | 03/24/2026, 00:00:00 UTC Added: 03/24/2026, 19:30:53 UTC |
0 CVE-2026-4531 is a medium-severity denial of service (DoS) vulnerability affecting Free5GC version 4.1.0, specifically in the AMF component's HandleRegistrationComplete function. The flaw allows an unauthenticated remote attacker to cause a DoS condition by manipulating the registration completion process. Exploitation does not require user interaction or privileges, and the attack surface is network-exposed. Although no known exploits are currently reported in the wild, the vulnerability could disrupt 5G core network availability. Applying the vendor patch identified by commit 52e9386401ce56ea773c5aa587d4cdf7d53da799 is recommended to mitigate this issue. Organizations deploying Free5GC 4.1.0 should prioritize patching to maintain service continuity and prevent potential network outages. Join the discussion | CVE Database V5 | 03/22/2026, 01:32:11 UTC Added: 03/22/2026, 01:45:50 UTC |
free5GC SMF provides Session Management Function for free5GC, an open-source project for 5th generation (5G) mobile core networks. In versions up to and including 1.4.1, SMF panics due to nil pointer dereference and the SMF process terminates. This is triggered by a malformed PFCP SessionReportRequest on the SMF PFCP (UDP/8805) interface. No known upstream fix is available, but some workarounds are available. ACL/firewall the PFCP interface so only trusted UPF IPs can reach SMF (reduce spoofing/abuse surface); drop/inspect malformed PFCP SessionReportRequest messages at the network edge where feasible, and/or add recover() around PFCP handler dispatch to avoid whole-process termination (mitigation only). Join the discussion | CVE Database V5 | 02/24/2026, 00:10:10 UTC Added: 02/24/2026, 00:47:47 UTC |
free5GC is an open-source project for 5th generation (5G) mobile core networks. Versions up to and including 1.4.1 of free5GC's AMF service have a Buffer Overflow vulnerability leading to Denial of Service. Remote unauthenticated attackers can crash the AMF service by sending a specially crafted NAS Registration Request with a malformed 5GS Mobile Identity, causing complete denial of service for the 5G core network. All deployments of free5GC using the AMF component may be affected. Pull request 43 of the free5gc/nas repo contains a fix. No direct workaround is available at the application level. Applying the official patch is recommended. Join the discussion | CVE Database V5 | 02/23/2026, 21:42:46 UTC Added: 02/23/2026, 21:47:15 UTC |
0 A weakness has been identified in Free5GC up to 4.1.0. Affected is the function SessionDeletionResponse of the component SMF. This manipulation causes null pointer dereference. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used for attacks. It is suggested to install a patch to address this issue. Join the discussion | CVE Database V5 | 02/06/2026, 03:02:11 UTC Added: 02/06/2026, 03:15:08 UTC |
0 A security flaw has been discovered in Free5GC up to 4.1.0. This impacts the function identityTriggerType of the file pfcp_reports.go. The manipulation results in null pointer dereference. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks. Applying a patch is advised to resolve this issue. Join the discussion | CVE Database V5 | 02/06/2026, 02:32:10 UTC Added: 02/06/2026, 03:15:08 UTC |
0 A vulnerability was determined in Free5GC up to 4.1.0. The impacted element is the function establishPfcpSession of the component SMF. Executing a manipulation can lead to null pointer dereference. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized. It is best practice to apply a patch to resolve this issue. Join the discussion | CVE Database V5 | 02/06/2026, 01:32:08 UTC Added: 02/06/2026, 02:15:09 UTC |
Showing 1 to 10 of 15 results