Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
CVE-2026-52758: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in nationalsecurityagency ghidraCVE-2026-52758 0 Ghidra before 12.1 contains a SQL injection vulnerability in BSim filter types that concatenate user-supplied values directly into SQL queries without escaping or parameterization. Remote attackers can inject arbitrary SQL via the BSim network query protocol to read, modify, or delete data in the PostgreSQL database. Join the discussion | CVE Database V5 | 06/10/2026, 12:42:30 UTC Added: 06/10/2026, 13:33:38 UTC |
CVE-2026-52757: Use After Free in nationalsecurityagency ghidraCVE-2026-52757 0 Ghidra before 12.1 contains a heap-use-after-free vulnerability in the decompiler's HighVariable::merge() function during the variable merging pass. Attackers can trigger this vulnerability by crafting a binary that causes stale pointers in the HighIntersectTest::highedgemap cache to be dereferenced, reading and writing the flags field of freed heap memory when a user opens the binary in Ghidra's decompiler view. Join the discussion | CVE Database V5 | 06/10/2026, 12:42:01 UTC Added: 06/10/2026, 13:33:38 UTC |
CVE-2026-52756: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in nationalsecurityagency ghidraCVE-2026-52756 0 Ghidra before 12.2 contains an unauthenticated path traversal vulnerability in the IsfServer that accepts TCP connections and passes client-supplied namespace strings directly to filesystem operations without validation. Remote attackers can connect to port 54321 and send crafted protobuf messages with traversal sequences to enumerate filesystem paths and probe arbitrary files. Join the discussion | CVE Database V5 | 06/10/2026, 12:41:39 UTC Added: 06/10/2026, 13:33:38 UTC |
CVE-2026-52755: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in nationalsecurityagency ghidraCVE-2026-52755 0 Ghidra before 12.0.4 contains a path traversal vulnerability in the theme import functionality that allows attackers to write files outside the intended theme directory. Attackers can craft malicious theme ZIP files with traversal sequences in filenames to execute arbitrary code or modify sensitive files like .bashrc or .ssh/authorized_keys. Join the discussion | CVE Database V5 | 06/10/2026, 12:41:11 UTC Added: 06/10/2026, 13:33:38 UTC |
CVE-2026-52754: Improper Verification of Cryptographic Signature in nationalsecurityagency ghidraCVE-2026-52754 0 Ghidra before 12.1 contains an authentication bypass vulnerability in PKIAuthenticationModule.authenticate() that allows any user with a valid CA-signed certificate to impersonate other users by presenting their public certificate with a null signature. Attackers can escalate privileges, modify repository access controls, exfiltrate shared reverse engineering databases, and permanently compromise server integrity. Join the discussion | CVE Database V5 | 06/10/2026, 12:40:46 UTC Added: 06/10/2026, 13:33:38 UTC |
CVE-2026-52753: Memory Allocation with Excessive Size Value in nationalsecurityagency ghidraCVE-2026-52753 0 Ghidra before 12.0.3 contains an out-of-memory vulnerability in the rust_demangle function that allocates unbounded output buffers without size limits. Attackers can craft malicious Rust symbol names in binaries to trigger exponential memory allocation, causing process crashes during binary analysis. Join the discussion | CVE Database V5 | 06/10/2026, 12:40:22 UTC Added: 06/10/2026, 13:33:34 UTC |
CVE-2026-52752: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in nationalsecurityagency ghidraCVE-2026-52752 0 Ghidra before 12.0.2 contains a path traversal vulnerability in the extension installer that fails to validate ZIP entry names during extraction. Attackers can craft malicious extensions with traversal sequences like ../ in filenames to write arbitrary files outside the intended directory, enabling code execution. Join the discussion | CVE Database V5 | 06/10/2026, 12:39:59 UTC Added: 06/10/2026, 13:33:34 UTC |
CVE-2026-52751: Deserialization of Untrusted Data in nationalsecurityagency ghidraCVE-2026-52751 0 Ghidra before 12.1 contains an unsafe deserialization vulnerability in client-side Shared-Project RMI connection code that allows unauthenticated remote code execution. Attackers can craft a malicious project file with a ghidra:// URL that, when opened via File → Open Project, deserializes untrusted objects using a Jython 2.7.4 gadget chain to execute arbitrary commands. Join the discussion | CVE Database V5 | 06/10/2026, 12:39:34 UTC Added: 06/10/2026, 13:33:34 UTC |
CVE-2026-52750: Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') in nationalsecurityagency ghidraCVE-2026-52750 0 Ghidra before 12.1 contains a command injection vulnerability in URL annotation handling on Windows where cmd.exe metacharacters are not properly escaped. Attackers can execute arbitrary commands under the Ghidra user's privileges by embedding malicious URLs in program comments that victims click. Join the discussion | CVE Database V5 | 06/10/2026, 12:39:03 UTC Added: 06/10/2026, 13:33:34 UTC |
CVE-2026-49498: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in nationalsecurityagency ghidraCVE-2026-49498 0 Ghidra 11.0 before 12.1 contains a SQL injection vulnerability in the changePassword() method of PostgresFunctionDatabase that fails to escape double quotes in usernames interpolated into ALTER ROLE statements. Authenticated attackers can inject SQL commands via crafted username parameters in PasswordChange network messages to escalate to PostgreSQL superuser privileges and gain full database control. Join the discussion | CVE Database V5 | 06/10/2026, 12:38:34 UTC Added: 06/10/2026, 13:33:34 UTC |
Showing 1 to 10 of 14 results