Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
0 A flaw was found in migration-planner. Insufficient validation of the `AgentStatusUpdate.CredentialUrl` field allows an authenticated attacker to store a malicious `javascript:` URL. When a victim views this URL in the Hybrid Cloud Console, it can lead to Cross-Site Scripting (XSS), enabling script execution in the victim's session and potentially disclosing sensitive information. Join the discussion | CVE Database V5 | 08/14/2026, 14:00:33 UTC Added: 08/14/2026, 14:27:14 UTC |
0 CVE-2026-53474 is a critical SQL Injection vulnerability in migration-planner that allows a remote authenticated attacker to execute malicious SQL by uploading a specially crafted RVTools .xlsx file. This flaw enables arbitrary file reading on the system, potentially exposing sensitive information such as Kubernetes service account tokens and credentials, which could lead to full compromise of the SaaS environment. The vulnerability affects versions prior to 0.13.5. Red Hat has assessed that this vulnerability does not impact any currently supported Red Hat products. A patch is available to address this issue. Join the discussion | CVE Database V5 | 06/10/2026, 15:31:33 UTC Added: 06/10/2026, 14:50:07 UTC |
CVE-2026-53471 is a critical authorization bypass vulnerability in migration-planner. The agent-API middleware fails to validate the source_id claim in JSON Web Tokens (JWTs) against the requested source ID in certain handlers. This flaw allows an authenticated attacker with a valid agent token to manipulate data across different tenants, breaking tenant isolation. Potential impacts include unauthorized overwriting of inventory, planting malicious credential URLs, or corrupting migration assessments. Red Hat has assessed that this vulnerability does not affect any currently supported Red Hat product. A patch is available for affected versions prior to 0.13.5. Join the discussion | CVE Database V5 | 06/10/2026, 15:31:33 UTC Added: 06/10/2026, 14:50:07 UTC |
CVE-2026-53470 is a critical authorization bypass vulnerability in the migration-planner cloud service affecting versions prior to 0.13.5. An authenticated attacker can exploit improper access control in the /api/v1/sources/{id}/image-url endpoint to bypass ownership checks and obtain presigned S3 URLs for OVA images belonging to other users. These images may contain sensitive data such as long-lived agent JWTs and source configurations, potentially enabling unauthorized access and modification of victim sources. A patch is available, and the vendor manages remediation for this cloud-hosted service. Join the discussion | CVE Database V5 | 06/10/2026, 15:31:33 UTC Added: 06/10/2026, 14:50:07 UTC |
0 CVE-2026-53469 is a critical vulnerability in migration-planner versions prior to 0.13.5. It allows an unauthenticated attacker to send a DELETE request to the /api/v1/sources endpoint, which lacks proper authorization and filtering. Exploitation results in the destruction of all customer data, including sources, agents, and assessments, causing a critical loss of availability and integrity of the SaaS platform. Join the discussion | CVE Database V5 | 06/10/2026, 13:55:37 UTC Added: 06/10/2026, 14:50:07 UTC |
Showing 1 to 5 of 5 results