Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
CVE-2026-53870: Incorrect Default Permissions in NousResearch hermes-agentCVE-2026-53870 0 Hermes Agent before 0.16.0 creates response_store.db and webhook_subscriptions.json with world-readable permissions (mode 0o644), exposing conversation history and HMAC secrets to local users. Attackers with local filesystem access can read these files directly to obtain sensitive data including conversation history, tool payloads, prompts, and per-route HMAC secrets. Join the discussion | CVE Database V5 | 06/17/2026, 17:57:58 UTC Added: 06/17/2026, 18:35:08 UTC |
CVE-2026-53869: Missing Authentication for Critical Function in NousResearch hermes-agentCVE-2026-53869 0 Hermes Agent versions before 0.16.0 contain a DNS rebinding vulnerability in WebSocket endpoints that bypasses Host and Origin validation. This occurs because FastAPI HTTP middleware does not run for WebSocket upgrade requests on certain API endpoints, allowing remote attackers to inject commands or read terminal output without authentication. Join the discussion | CVE Database V5 | 06/17/2026, 17:57:30 UTC Added: 06/17/2026, 18:35:08 UTC |
CVE-2026-10548: Improper Authentication in NousResearch hermes-agentCVE-2026-10548 0 A security flaw has been discovered in NousResearch hermes-agent up to 2026.4.23. This affects the function _sync_anthropic_entry_from_credentials_file of the file agent/credential_pool.py of the component Credential Pool Synchronization. The manipulation results in improper authentication. The attack must be initiated from a local position. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way. Join the discussion | CVE Database V5 | 06/02/2026, 00:30:09 UTC Added: 06/02/2026, 01:33:33 UTC |
CVE-2026-10220: Injection in NousResearch hermes-agentCVE-2026-10220 0 A vulnerability was determined in NousResearch hermes-agent up to 2026.4.30. Affected is the function _serve_plugin_skill/skill_view of the file tools/skills_tool.py. Executing a manipulation can lead to injection. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way. Join the discussion | CVE Database V5 | 06/01/2026, 03:30:09 UTC Added: 06/01/2026, 19:52:46 UTC |
CVE-2026-10224: Resource Consumption in NousResearch hermes-agentCVE-2026-10224 0 A security vulnerability has been detected in NousResearch hermes-agent up to 2026.4.30. This vulnerability affects the function _handle_webhook_request of the file gateway/platforms/feishu.py of the component Webhook Endpoint. Such manipulation leads to resource consumption. The attack can be launched remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way. Join the discussion | CVE Database V5 | 06/01/2026, 04:30:08 UTC Added: 06/01/2026, 05:33:33 UTC |
CVE-2026-9369: Incorrect Comparison in NousResearch hermes-agentCVE-2026-9369 0 A security flaw has been discovered in NousResearch hermes-agent 2026.4.23. Affected is the function _discover_dashboard_plugins of the file hermes_cli/web_server.py of the component CLI web-dashboard Interface. Performing a manipulation of the argument HERMES_ENABLE_PROJECT_PLUGINS results in incorrect comparison. The attack is only possible with local access. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way. Join the discussion | CVE Database V5 | 05/24/2026, 09:00:16 UTC Added: 05/24/2026, 09:16:37 UTC |
CVE-2026-9368: Sandbox Issue in NousResearch hermes-agentCVE-2026-9368 0 A vulnerability was identified in NousResearch hermes-agent up to 2026.4.16. This impacts the function execute_code of the file tools/code_execution_tool.py of the component Environment Variable Handler. Such manipulation leads to sandbox issue. It is possible to launch the attack remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way. Join the discussion | CVE Database V5 | 05/24/2026, 08:45:09 UTC Added: 05/24/2026, 09:16:37 UTC |
CVE-2026-9366: Injection in NousResearch hermes-agentCVE-2026-9366 0 A vulnerability was found in NousResearch hermes-agent 2026.4.23. The impacted element is the function _scan_context_content of the file agent/prompt_builder.py. The manipulation results in injection. The attack may be performed from remote. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way. Join the discussion | CVE Database V5 | 05/24/2026, 08:15:09 UTC Added: 05/24/2026, 09:16:37 UTC |
CVE-2026-9354: Escaping of Output in NousResearch hermes-agentCVE-2026-9354 0 A vulnerability was detected in NousResearch hermes-agent up to 2026.4.16. The affected element is an unknown function of the component Slack Agent/Mattermost Agent. The manipulation of the argument format_message results in escaping of output. The attack can be executed remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. Join the discussion | CVE Database V5 | 05/24/2026, 04:15:07 UTC Added: 05/24/2026, 05:01:37 UTC |
CVE-2026-9353: Injection in NousResearch hermes-agentCVE-2026-9353 0 A security vulnerability has been detected in NousResearch hermes-agent up to 2026.4.23. Impacted is an unknown function of the file agent/skills_guard.py of the component Skills Guard Multi-Word Prompt Handler. The manipulation of the argument THREAT_PATTERNS leads to injection. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way. Join the discussion | CVE Database V5 | 05/24/2026, 03:45:07 UTC Added: 05/24/2026, 05:01:37 UTC |
Showing 1 to 10 of 12 results