Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
Docker Engine classifies a registry hostname as insecure using an any-match DNS check. loadInsecureRegistries() injects 127.0.0.0/8 and ::1/128 as insecure CIDRs by default. isCIDRMatch resolves all of the hostname's addresses and returns true if a single address is in the insecure CIDR list. Because the transport re-dials the hostname rather than the CIDR-matching address, a DNS answer set of one loopback IP plus a non-loopback attacker IP disables certificate verification and enables HTTP fallback for the registry connection. Join the discussion | CVE Database V5 | 10/07/2026, 16:44:21 UTC Added: 10/07/2026, 17:19:15 UTC |
0 Miniflux v2 before version 2.3.1 contains an open redirect vulnerability due to improper handling of redirect URLs with backslashes. This allows an unauthenticated attacker to bypass relative-path and host checks in the login flow and redirect users to attacker-controlled external sites. The issue is fixed in version 2.3.1. Join the discussion | CVE Database V5 | 08/21/2026, 20:19:14 UTC Added: 08/21/2026, 20:37:40 UTC |
A flaw was found in github.com/go-viper/mapstructure/v2, in the field processing component using mapstructure.WeakDecode. This vulnerability allows information disclosure through detailed error messages that may leak sensitive input values via malformed user-supplied data processed in security-critical contexts. Join the discussion | CVE Database V5 | 01/26/2026, 19:36:28 UTC Added: 01/26/2026, 19:50:57 UTC |
Miniflux 2 is an open source feed reader. Prior to version 2.2.16, Miniflux's media proxy endpoint (`GET /proxy/{encodedDigest}/{encodedURL}`) can be abused to perform Server-Side Request Forgery (SSRF). An authenticated user can cause Miniflux to generate a signed proxy URL for attacker-chosen media URLs embedded in feed entry content, including internal addresses (e.g., localhost, private RFC1918 ranges, or link-local metadata endpoints). Requesting the resulting `/proxy/...` URL makes Miniflux fetch and return the internal response. Version 2.2.16 fixes the issue. Join the discussion | CVE Database V5 | 01/08/2026, 13:57:25 UTC Added: 01/08/2026, 14:05:31 UTC |
0 Miniflux 2 is an open source feed reader. Versions 2.2.14 and below treat redirect_url as safe when url.Parse(...).IsAbs() is false, enabling phishing flows after login. Protocol-relative URLs like //ikotaslabs.com have an empty scheme and pass that check, allowing post-login redirects to attacker-controlled sites. This issue is fixed in version 2.2.15. Join the discussion | CVE Database V5 | 12/11/2025, 00:17:00 UTC Added: 12/11/2025, 00:23:37 UTC |
Showing 1 to 5 of 5 results