Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
CVE-2026-18613: Injection in GL-iNet GL-MT3000CVE-2026-18613 0 CVE-2026-18613 is a critical remote injection vulnerability in the GL-iNet GL-MT3000 device affecting versions 4.4.0 through 4.4.5. The flaw exists in the plugins.set_config function within the /cgi-bin/glc file of the plugins.so Native Plugin component. This vulnerability allows an attacker to perform injection attacks remotely without any privileges or user interaction. The vulnerability has been publicly disclosed and confirmed by the vendor, but no official patch or remediation guidance has been provided yet. Join the discussion | CVE Database V5 | 08/03/2026, 17:45:09 UTC Added: 08/03/2026, 19:26:37 UTC |
CVE-2026-18616: Command Injection in GL-iNet GL-MT3000CVE-2026-18616 0 A vulnerability was identified in GL-iNet GL-MT3000 up to 4.4.5. The impacted element is the function server.set_peer of the file /cgi-bin/glc of the component wg-server.so Native Plugin. The manipulation of the argument public_key leads to command injection. Remote exploitation of the attack is possible. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure and confirmed the existence of the vulnerability. Join the discussion | CVE Database V5 | 08/03/2026, 18:30:10 UTC Added: 08/03/2026, 19:03:37 UTC |
CVE-2026-18615: Command Injection in GL-iNet GL-MT3000CVE-2026-18615 0 A vulnerability was determined in GL-iNet GL-MT3000 up to 4.4.5. The affected element is the function wg-server.generate_publickey of the file /cgi-bin/glc of the component wg-server.so Native Plugin. Executing a manipulation of the argument private_key can lead to command injection. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure and confirmed the existence of the vulnerability. Join the discussion | CVE Database V5 | 08/03/2026, 18:15:08 UTC Added: 08/03/2026, 18:33:33 UTC |
CVE-2026-18614: Command Injection in GL-iNet GL-MT3000CVE-2026-18614 0 A vulnerability was found in GL-iNet GL-MT3000 up to 4.4.5. Impacted is the function s2s.enable_echo_server of the file /cgi-bin/glc of the component s2s.so Native Plugin. Performing a manipulation of the argument port results in command injection. The attack may be initiated remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure and confirmed the existence of the vulnerability. Join the discussion | CVE Database V5 | 08/03/2026, 18:00:09 UTC Added: 08/03/2026, 18:33:33 UTC |
CVE-2026-18602: Command Injection in GL.iNet GL-MT3000CVE-2026-18602 0 A vulnerability was determined in GL.iNet GL-MT3000 up to 4.4.5. Affected is the function ovpn-client.get_recommend_config of the file /cgi-bin/glc of the component ovpn-client.so Native Plugin. Executing a manipulation of the argument Hostname can lead to command injection. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure and confirmed the existence of the vulnerability. Join the discussion | CVE Database V5 | 08/03/2026, 15:30:08 UTC Added: 08/03/2026, 16:18:42 UTC |
CVE-2026-18599: Command Injection in GL.iNet GL-MT3000CVE-2026-18599 0 A flaw has been found in GL.iNet GL-MT3000 up to 4.4.5. The impacted element is the function logread.set_config of the file /usr/lib/oui-httpd/rpc/logread of the component Logread Lua RPC Plugin. This manipulation of the argument record_size causes command injection. The exploit has been published and may be used. The vendor was contacted early about this disclosure and confirmed the existence of the vulnerability. Join the discussion | CVE Database V5 | 08/03/2026, 12:00:09 UTC Added: 08/03/2026, 12:48:47 UTC |
Showing 1 to 6 of 6 results