Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
0 CVE-2026-58041 is a medium severity vulnerability in Node.js affecting versions 22.x, 24.x, and 26.x. It involves a time-of-check to time-of-use (TOCTOU) race condition in the node:sqlite module, where a stale StatementSyncIterator can continue executing a cached prepared statement after it has been reset and rebound with new parameters. This occurs because SQLTagStore resets cached statements using sqlite3_reset() directly, bypassing the iterator invalidation mechanism introduced in recent releases. Join the discussion | CVE Database V5 | 08/04/2026, 00:49:58 UTC Added: 08/04/2026, 01:03:31 UTC |
0 Improper authorization in the /tequilapi/config/user endpoint of Mysterium Node from v1.21.1-rc0 before v1.36.0 allows an unauthenticated attacker to arbitrarily overwrite the node's configuration and achieve a full node takeover via a crafted POST request. Join the discussion | CVE Database V5 | 07/08/2026, 00:00:00 UTC Added: 07/08/2026, 22:13:57 UTC |
A flaw in Node.js TLS hostname handling can cause Embedded-nul hostnames can lead to silent authority rebinding due to c-string truncation in resolver bindings. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**. Join the discussion | CVE Database V5 | 06/26/2026, 01:14:37 UTC Added: 06/26/2026, 01:31:11 UTC |
A inconsistency in Node.js hostname matching can cause a trust-policy bypass in multi-context mTLS setups. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**. Join the discussion | CVE Database V5 | 06/26/2026, 01:14:36 UTC Added: 06/26/2026, 01:31:11 UTC |
A flaw in Node.js HTTP/2 client allows a server to send an unlimited number of ORIGIN frames, which could lead to an Out of Memory error on the client. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**. Join the discussion | CVE Database V5 | 06/26/2026, 01:14:36 UTC Added: 06/26/2026, 01:31:11 UTC |
0 A flaw in Node.js proxy tunnel error handling could expose proxy credentials in `ERR_PROXY_TUNNEL` error messages. When proxy credentials are embedded in the proxy URL, they may be exposed through error handling paths and captured by logs, diagnostics, or other error consumers. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**. Join the discussion | CVE Database V5 | 06/26/2026, 01:14:36 UTC Added: 06/26/2026, 01:31:11 UTC |
0 A flaw in Node.js HTTP Agent can cause a client to accept as valid a response that is send before the client has sent the request. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**. Join the discussion | CVE Database V5 | 06/22/2026, 18:59:30 UTC Added: 06/22/2026, 19:55:50 UTC |
A flaw in Node.js HTTP/2 server API can cause servers to keep accepting data even after sending a `GOAWAY` frame. This vulnerability affects two supported release lines: **Node.js 22** and **Node.js 24**. Join the discussion | CVE Database V5 | 06/18/2026, 18:01:39 UTC Added: 06/18/2026, 18:52:19 UTC |
A flaw in Node.js Permission Model enforcement allows Bypass via `process.report.writeReport()` Path Misvalidation. This can lead to confidentiality impact or bypass of the intended security boundary under affected configurations. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**. Join the discussion | CVE Database V5 | 06/18/2026, 16:21:12 UTC Added: 06/18/2026, 16:36:21 UTC |
0 A flaw in Node.js URL processing causes an assertion failure in native code when `url.format()` is called with a malformed internationalized domain name (IDN) containing invalid characters, crashing the Node.js process. Join the discussion | CVE Database V5 | 03/30/2026, 16:16:00 UTC Added: 03/30/2026, 15:53:19 UTC |
Showing 1 to 10 of 13 results