Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
CVE-2026-74901: Improper Verification of Cryptographic Signature in jahlives openssl_encryptCVE-2026-74901 0 openssl_encrypt versions before 1.4.0 contain an authentication bypass vulnerability in pqc.py where AES-GCM decryption failures trigger fallback to unauthenticated AES-CTR mode. Attackers can modify ciphertext in transit to bypass integrity verification and perform bit-flipping attacks without detection. Join the discussion | CVE Database V5 | 08/17/2026, 11:04:59 UTC Added: 08/17/2026, 11:27:02 UTC |
CVE-2026-74895: Protection Mechanism Failure in jahlives openssl_encryptCVE-2026-74895 0 openssl_encrypt versions before 1.4.0 fail to apply sandbox restrictions in the default process isolation mode for plugin execution. Attackers can execute malicious plugins with unrestricted access to the filesystem, network, subprocess execution, and all Python modules. Join the discussion | CVE Database V5 | 08/17/2026, 11:04:57 UTC Added: 08/17/2026, 11:27:02 UTC |
CVE-2026-74893: Use of Hard-coded Credentials in jahlives openssl_encryptCVE-2026-74893 0 openssl_encrypt versions before 1.4.0 contain hardcoded default JWT signing secrets in config.py that pass validation checks. Attackers with access to source code can forge valid JWT tokens for any client_id to gain authenticated access to keyserver and telemetry APIs. Join the discussion | CVE Database V5 | 08/17/2026, 11:04:55 UTC Added: 08/17/2026, 11:27:02 UTC |
CVE-2026-74889: Inadequate Encryption Strength in jahlives openssl_encryptCVE-2026-74889 0 openssl_encrypt versions before 1.4.0 use HKDF with no salt and static info parameter in key normalization functions, reducing entropy extraction and determinism. Attackers can exploit predictable key derivation with identical inputs to weaken cryptographic security against multi-target attacks. Join the discussion | CVE Database V5 | 08/17/2026, 11:04:53 UTC Added: 08/17/2026, 11:27:00 UTC |
CVE-2026-74887: Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG) in jahlives openssl_encryptCVE-2026-74887 0 openssl_encrypt before 1.4.0 imports Python's non-cryptographic 'random' module (Mersenne Twister PRNG) at line 15 of openssl_encrypt/modules/pqc.py. No direct calls to random.* were present in the code, so no cryptographic operation is currently affected; however, the import creates a hazard that future code could inadvertently use random.randint() instead of a cryptographically secure alternative (secrets/os.urandom), producing predictable values since the Mersenne Twister state can be recovered from approximately 624 outputs. Fixed by removing the import in 1.4.0. Join the discussion | CVE Database V5 | 08/17/2026, 11:04:51 UTC Added: 08/17/2026, 11:27:00 UTC |
CVE-2026-74884: External Control of File Name or Path in jahlives openssl_encryptCVE-2026-74884 0 openssl_encrypt versions before 1.4.0 contain a path traversal vulnerability in the _is_safe_path method where the plugin_id parameter is not sanitized before constructing the plugin config directory path. Attackers can declare a malicious plugin_id containing path traversal sequences like '../' to access arbitrary directories outside the intended plugin directory. Join the discussion | CVE Database V5 | 08/17/2026, 11:04:49 UTC Added: 08/17/2026, 11:27:00 UTC |
CVE-2026-74883: Protection Mechanism Failure in jahlives openssl_encryptCVE-2026-74883 0 openssl_encrypt versions before 1.4.0 contain a sandbox bypass vulnerability where the plugin sandbox fails to restrict alternative file access methods like pathlib.Path and io.open. Attackers can import pathlib or io modules to read and write arbitrary files, completely bypassing the restricted_open file access controls. Join the discussion | CVE Database V5 | 08/17/2026, 11:04:49 UTC Added: 08/17/2026, 11:27:00 UTC |
CVE-2026-74882: Insufficient Verification of Data Authenticity in jahlives openssl_encryptCVE-2026-74882 0 openssl_encrypt versions before 1.4.0 contain an insecure default configuration that trusts the entire RFC 1918 private address space in IntegrityProxyConfig trusted_proxies. Attackers on private networks can forge client certificate headers to bypass mTLS authentication when ProxyAuth validation is relaxed or modified. Join the discussion | CVE Database V5 | 08/17/2026, 11:04:48 UTC Added: 08/17/2026, 11:27:00 UTC |
CVE-2026-74881: Permissive Cross-domain Security Policy with Untrusted Domains in jahlives openssl_encryptCVE-2026-74881 0 openssl_encrypt versions before 1.4.0 configure CORS with allow_origins set to wildcard and allow_credentials enabled to true. Attackers can create malicious websites that make authenticated cross-origin requests to the API on behalf of any user who visits them. Join the discussion | CVE Database V5 | 08/17/2026, 11:04:47 UTC Added: 08/17/2026, 11:26:59 UTC |
CVE-2026-74878: Allocation of Resources Without Limits or Throttling in jahlives openssl_encryptCVE-2026-74878 0 openssl_encrypt versions before 1.4.0 use an in-memory rate limiter for TOTP brute-force protection that is not shared across workers and is lost on server restart. Attackers can distribute authentication attempts across multiple server instances or retry immediately after a restart to bypass rate limiting protections. Join the discussion | CVE Database V5 | 08/17/2026, 11:04:45 UTC Added: 08/17/2026, 11:26:59 UTC |
Showing 1 to 10 of 13 results