Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
0 CVE-2026-54575 is an OS command injection vulnerability in MidnightBSD's mport package manager prior to version 2.7.8. The flaw arises from race conditions in path handling during privileged package fetch and cache-cleaning operations, combined with shell-form command invocation. A local attacker with write access to package cache or staging paths could exploit this to redirect package-related operations outside intended directories. This vulnerability is fixed in version 2.7.8. Join the discussion | CVE Database V5 | 09/17/2026, 16:55:19 UTC Added: 09/17/2026, 17:02:24 UTC |
0 CVE-2026-54578 is a low-severity vulnerability in MidnightBSD's mport package manager prior to version 2.7.8. The issue involves improper validation of integrity check values where the verification function may continue after a hashing failure and compare expected checksums against stale data. This could allow an attacker who can influence installed files or hashing conditions to receive misleading integrity results or conceal checksum failures. The vulnerability is fixed in version 2.7.8. Join the discussion | CVE Database V5 | 09/17/2026, 16:54:20 UTC Added: 09/17/2026, 17:02:24 UTC |
0 CVE-2026-54586 is a vulnerability in the MidnightBSD package manager mport prior to version 2.7.8. The issue involves the acceptance of non-HTTPS URLs for repository and package mirrors, allowing cleartext transmission of sensitive information. This could enable a network attacker to tamper with package index or download traffic, potentially compromising package selection or integrity. The vulnerability is fixed in version 2.7.8. Join the discussion | CVE Database V5 | 09/17/2026, 16:53:24 UTC Added: 09/17/2026, 17:02:24 UTC |
0 mport is the MidnightBSD Package Manager. Prior to 2.7.8, create_sample_file() in libmport/bundle_read_install_pkg.c did not constrain absolute source and destination paths from the sample-file manifest directive to mport->root. A malicious or malformed package manifest could therefore direct privileged sample-file handling to copy or write outside the configured installation root, compromising local filesystem integrity. This issue is fixed in version 2.7.8. Join the discussion | CVE Database V5 | 09/17/2026, 16:52:33 UTC Added: 09/17/2026, 17:02:24 UTC |
0 CVE-2026-54580 is a vulnerability in MidnightBSD's mport package manager prior to version 2.7.8. The issue involves improper validation of integrity check values during decompression of compressed package index data. Specifically, failures in decompressing or writing output were not always treated as fatal, allowing partial corrupted index data to be used. This can lead to package index integrity loss or denial of service. The vulnerability is fixed in version 2.7.8. Join the discussion | CVE Database V5 | 09/17/2026, 16:51:29 UTC Added: 09/17/2026, 17:02:24 UTC |
mport is the MidnightBSD Package Manager. Prior to 2.7.8, package installation lacked a preflight check for incoming non-directory assets that already existed on disk. The affected logic across libmport/check_preconditions.c, libmport/install_primative.c, and libmport/mport_private.h did not apply MPORT_PRECHECK_FILE_CONFLICTS, so a crafted or conflicting package could overwrite a file owned by another package or unmanaged by mport. The check is bypassed only when the operator explicitly enables mport->force. Privileged installation without that override could compromise local filesystem integrity and package database consistency. This issue is fixed in version 2.7.8. Join the discussion | CVE Database V5 | 09/17/2026, 16:50:40 UTC Added: 09/17/2026, 17:02:24 UTC |
CVE-2026-54577 is a low-severity vulnerability in the MidnightBSD package manager mport prior to version 2.7.8. The issue involves improper input validation in the audit command, where option parsing errors could cause the tool to audit an option token instead of the intended package name. This results in false-negative or useless audit results, potentially leaving vulnerable packages unidentified. The vulnerability is fixed in version 2.7.8 by resetting parsing state before processing arguments. Join the discussion | CVE Database V5 | 09/17/2026, 16:49:48 UTC Added: 09/17/2026, 17:02:24 UTC |
0 CVE-2026-54583 is a path traversal vulnerability in the MidnightBSD package manager 'mport' prior to version 2.7.8. The vulnerability arises because the software did not consistently validate bundle filenames, allowing malicious package index data to specify unsafe filenames. This could lead to downloaded package data being written outside the intended cache directory or to unsafe locations. The issue is fixed in version 2.7.8. Join the discussion | CVE Database V5 | 09/17/2026, 16:46:28 UTC Added: 09/17/2026, 17:02:24 UTC |
0 mport is the MidnightBSD Package Manager. Prior to 2.7.8, the mport_fetch_bootstrap_index() function in libmport/fetch.c could return success when bootstrap index hash verification encountered a missing or invalid hash because the failure path did not preserve a fatal result. A network attacker or compromised mirror able to alter bootstrap index content or its transport path could therefore cause mport to proceed with an unverified or tampered bootstrap package index. This issue is fixed in version 2.7.8. Join the discussion | CVE Database V5 | 09/17/2026, 16:45:37 UTC Added: 09/17/2026, 17:02:24 UTC |
Showing 1 to 9 of 9 results