Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
NebulaGraph versions up to 3.8.0 expose a runtime configuration HTTP service without any authentication, allowing unauthenticated access to read and modify critical runtime flags. This includes sensitive information such as certificate paths and password files, and enables changing daemon behavior like disabling transport security or altering login attempt limits. The vulnerability has a critical severity with a CVSS score of 9.3. No official patch or remediation guidance is currently available. Join the discussion | CVE Database V5 | 08/26/2026, 15:45:00 UTC Added: 08/26/2026, 15:53:01 UTC |
0 TIER IV Nebula versions up to 1.2.0 contain an out-of-bounds read vulnerability in the Vlp32Decoder::unpack() function. This flaw allows unauthenticated remote attackers to send short UDP datagrams to the Velodyne UDP sensor port, causing the decoder to read beyond the buffer into adjacent heap memory. As a result, fabricated point data derived from heap memory may be published into PointCloud2 messages consumed by Autoware nodes. Join the discussion | CVE Database V5 | 08/17/2026, 18:12:37 UTC Added: 08/17/2026, 18:26:57 UTC |
0 Nebula is a scalable overlay networking tool. In versions from 1.7.0 to 1.10.2, when using P256 certificates (which is not the default configuration), it is possible to evade a blocklist entry created against the fingerprint of a certificate by using ECDSA Signature Malleability to use a copy of the certificate with a different fingerprint. This issue has been patched in version 1.10.3. Join the discussion | CVE Database V5 | 02/06/2026, 22:55:36 UTC Added: 02/06/2026, 23:00:08 UTC |
Slack Nebula before 1.9.7 mishandles CIDR in some configurations and thus accepts arbitrary source IP addresses within the Nebula network. Join the discussion | CVE Database V5 | 10/23/2025, 00:00:00 UTC Added: 10/23/2025, 04:07:02 UTC |
0 An issue was discovered in vesoft NebulaGraph through 3.8.0. It allows bypassing authentication. Join the discussion | CVE Database V5 | 09/22/2024, 00:00:00 UTC Added: 02/25/2026, 21:43:36 UTC |
Showing 1 to 5 of 5 results