Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
NAVTOR NavBox versions up to and including 4.16.1.20 contain hard-coded credentials in their Windows Communication Foundation (SOAP) implementation. If SOAP functionality is enabled, a local attacker can extract these credentials to bypass intended transfer workflows. Successful authentication via the SOAP interface allows access to privileged methods that can write or overwrite files within application-defined paths. This vulnerability has a medium severity rating with a CVSS score of 5.8. Join the discussion | CVE Database V5 | 06/04/2026, 19:44:53 UTC Added: 06/04/2026, 21:03:37 UTC |
Navtor NavBox exposes sensitive configuration and operational data due to missing authentication on HTTP API endpoints. An unauthenticated remote attacker with network access to the device can execute HTTP GET requests to TCP port 8080 to retrieve internal network parameters including ECDIS & OT Information, device identifiers, and service status logs. Join the discussion | CVE Database V5 | 03/06/2026, 15:05:20 UTC Added: 03/06/2026, 15:16:07 UTC |
An Absolute Path Traversal vulnerability exists in Navtor NavBox. The application exposes an HTTP service that fails to properly sanitize user-supplied path input. Unauthenticated remote attackers can exploit this issue by submitting requests containing absolute filesystem paths. Successful exploitation allows the attacker to retrieve arbitrary files from the underlying filesystem, limited only by the privileges of the service process. This can lead to the exposure of sensitive configuration files and system information. Join the discussion | CVE Database V5 | 03/06/2026, 15:04:47 UTC Added: 03/06/2026, 15:16:07 UTC |
0 Navtor NavBox allows information disclosure via the /api/ais-data endpoint. A remote, unauthenticated attacker can send crafted requests to trigger an unhandled exception, causing the server to return verbose .NET stack traces. These error messages expose internal class names, method calls, and third-party library references (e.g., System.Data.SQLite), which may assist attackers in mapping the application's internal structure. Join the discussion | CVE Database V5 | 03/06/2026, 15:04:20 UTC Added: 03/06/2026, 15:16:07 UTC |
Showing 1 to 4 of 4 results