Skip to main content

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Package: pkg:github/migration-planner

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

A flaw was found in migration-planner. Insufficient validation of the `AgentStatusUpdate.CredentialUrl` field allows an authenticated attacker to store a malicious `javascript:` URL. When a victim views this URL in the Hybrid Cloud Console, it can lead to Cross-Site Scripting (XSS), enabling script execution in the victim's session and potentially disclosing sensitive information.

Join the discussion

CVE-2026-53474 is a critical SQL Injection vulnerability in migration-planner that allows a remote authenticated attacker to execute malicious SQL by uploading a specially crafted RVTools .xlsx file. This flaw enables arbitrary file reading on the system, potentially exposing sensitive information such as Kubernetes service account tokens and credentials, which could lead to full compromise of the SaaS environment. The vulnerability affects versions prior to 0.13.5. Red Hat has assessed that this vulnerability does not impact any currently supported Red Hat products. A patch is available to address this issue.

Join the discussion

CVE-2026-53471 is a critical authorization bypass vulnerability in migration-planner. The agent-API middleware fails to validate the source_id claim in JSON Web Tokens (JWTs) against the requested source ID in certain handlers. This flaw allows an authenticated attacker with a valid agent token to manipulate data across different tenants, breaking tenant isolation. Potential impacts include unauthorized overwriting of inventory, planting malicious credential URLs, or corrupting migration assessments. Red Hat has assessed that this vulnerability does not affect any currently supported Red Hat product. A patch is available for affected versions prior to 0.13.5.

Join the discussion

CVE-2026-53470 is a critical authorization bypass vulnerability in the migration-planner cloud service affecting versions prior to 0.13.5. An authenticated attacker can exploit improper access control in the /api/v1/sources/{id}/image-url endpoint to bypass ownership checks and obtain presigned S3 URLs for OVA images belonging to other users. These images may contain sensitive data such as long-lived agent JWTs and source configurations, potentially enabling unauthorized access and modification of victim sources. A patch is available, and the vendor manages remediation for this cloud-hosted service.

Join the discussion

CVE-2026-53469 is a critical vulnerability in migration-planner versions prior to 0.13.5. It allows an unauthenticated attacker to send a DELETE request to the /api/v1/sources endpoint, which lacks proper authorization and filtering. Exploitation results in the destruction of all customer data, including sources, agents, and assessments, causing a critical loss of availability and integrity of the SaaS platform.

Join the discussion

Showing 1 to 5 of 5 results

Filters:Package: pkg:github/migration-planner
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses