Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
CVE-2026-73974 is a path traversal vulnerability in linuxfabrik monitoring-plugins prior to version 7.0.0 and linuxfabrik-lib prior to 6.1.0. The issue arises because the test helper function lib.lftest.test() improperly handles filesystem paths from a hidden --test argument, allowing unauthorized file reads without path confinement. This vulnerability enables an attacker with sudo-authorized plugin access to read arbitrary root-readable files. The flaw affects multiple plugins that expose file content or existence checks. The vulnerability is fixed by confining fixture reads to a safe directory and routing bypasses through the helper in the fixed versions. Join the discussion | CVE Database V5 | 08/18/2026, 21:15:03 UTC Added: 08/18/2026, 21:35:07 UTC |
Linuxfabrik monitoring-plugins prior to version 7.0.0 contain a path traversal vulnerability in the logfile check plugin. The plugin accepts a free-form --filename argument and opens the specified file as root without restricting the path to /var/log. This allows an attacker with control over the monitoring account to read arbitrary root-readable files such as /etc/shadow. The issue is fixed in version 7.0.0 by confining paths to documented log roots and resolving symlinks and parent-directory traversal before access. Join the discussion | CVE Database V5 | 08/18/2026, 21:12:27 UTC Added: 08/18/2026, 21:35:07 UTC |
CVE-2026-67436 is a high-severity vulnerability in Linuxfabrik monitoring-plugins version 6.0.0 and earlier. The redfish-* plugins construct request URLs by concatenating an operator-supplied base URL with response-supplied @odata.id links. This improper input validation allows a malicious or compromised Baseboard Management Controller (BMC) to redirect authenticated Redfish requests, potentially exposing X-Auth-Token or HTTP Basic credentials. Join the discussion | CVE Database V5 | 07/29/2026, 19:43:35 UTC Added: 07/29/2026, 21:00:27 UTC |
0 CVE-2026-67433 is a medium severity vulnerability in Linuxfabrik monitoring-plugins version 6.0.0. It involves improper link resolution before file access, where a local user controlling the plugin account can create a symbolic link in a predictable /tmp path. This symlink is followed by sqlite3.connect() during a root-run check, potentially leading to unauthorized file access or modification. Join the discussion | CVE Database V5 | 07/29/2026, 19:27:41 UTC Added: 07/29/2026, 21:00:27 UTC |
Showing 1 to 4 of 4 results