Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
hashcat fails to restrict command-line options when parsing restore files, allowing attackers to inject output-redirecting options like --outfile and --potfile-path. Attackers can craft restore files with malicious options to append attacker-controlled content to arbitrary files, enabling code execution when targeting shell startup files. Join the discussion | GCVE Database | 08/22/2026, 15:31:04 UTC Added: 08/22/2026, 22:51:34 UTC |
hashcat's fgetl() function in src/filehandling.c writes a null terminator one byte past the caller's buffer when an input line is exactly the buffer length. Attackers can trigger this out-of-bounds heap write by providing a hash file, potfile, or wordlist containing a line of exactly HCBUFSIZ_LARGE bytes. Join the discussion | GCVE Database | 08/22/2026, 15:31:04 UTC Added: 08/22/2026, 22:51:32 UTC |
Hashcat master branch builds after version 7.1.2 contain a heap buffer overflow vulnerability in the KeePass AESKDF/KDBX v4 module (module 34301). This vulnerability arises from improper handling of the ninth hash field token, which can overflow a fixed 256-byte buffer by up to 44 bytes. The overflow can corrupt adjacent heap memory, potentially causing heap corruption or memory access violations. The vulnerability has a CVSS score of 6.1, indicating medium severity. Join the discussion | GCVE Database | 08/17/2026, 21:31:26 UTC Added: 08/17/2026, 22:33:24 UTC |
0 A heap-based buffer overflow in hex_to_binary in the PKZIP hash parser in hashcat v7.1.2 allows an attacker to cause a denial of service or possibly execute arbitrary code via a crafted PKZIP hash file. The issue affects modules 17200, 17210, 17220, 17225, and 17230. When data_type_enum<=1, attacker-controlled hex data from a user-supplied hash string is decoded into a fixed-size buffer without proper input-length validation. Join the discussion | CVE Database V5 | 05/01/2026, 00:00:00 UTC Added: 05/01/2026, 14:22:54 UTC |
0 A heap-based buffer overflow in the Kerberos hash parser in hashcat v7.1.2 allows an attacker to cause a denial of service or possibly execute arbitrary code via a crafted Kerberos hash file. The issue affects module_hash_decode in multiple Kerberos-related modules because account_info_len is calculated from untrusted delimiter positions without upper-bound validation before memcpy copies the data into a fixed-size account_info buffer. Join the discussion | CVE Database V5 | 05/01/2026, 00:00:00 UTC Added: 05/01/2026, 14:22:54 UTC |
0 A stack-based buffer overflow in mangle_to_hex_lower() and mangle_to_hex_upper() in src/rp_cpu.c in hashcat v7.1.2 allows an attacker to cause a denial of service or possibly execute arbitrary code via a crafted rule file, or via the -j or -k rule options used with password candidates of 128 or more characters. The vulnerability is caused by a bounds check that fails to account for the 2x expansion that occurs when password bytes are converted to hexadecimal. Join the discussion | CVE Database V5 | 05/01/2026, 00:00:00 UTC Added: 05/01/2026, 14:22:54 UTC |
Showing 1 to 6 of 6 results