Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
CVE-2026-84942 is a high-severity cross-site scripting (XSS) vulnerability in AWS Amazon OpenSearch Service affecting the Vega expression function implementation in OpenSearch Dashboards. It allows a remote authenticated user with dashboard write permissions to execute arbitrary JavaScript in other users' browsers by saving a specially crafted Vega visualization. The vulnerability arises because the input validation routine failed to properly inspect nested arrays, allowing malicious function properties to bypass checks. This can lead to complete compromise of user sessions without impacting availability. Join the discussion | CVE Database V5 | 09/08/2026, 19:41:25 UTC Added: 09/08/2026, 19:52:45 UTC |
0 CVE-2026-77811 is a stored cross-site scripting (XSS) vulnerability in the dashboards-observability plugin of OpenSearch Dashboards. It allows a remote authenticated user with write permissions to upload a custom integration containing arbitrary JavaScript. When other users access the affected static file endpoint, the malicious script executes in their browser, potentially performing actions on their behalf with their privileges. This affects self-managed OpenSearch Dashboards versions before 3.4 and 2.19.6, and Amazon OpenSearch Service versions before 3.3. The issue has been fixed in OpenSearch Dashboards versions 3.4 and 2.19.6 and all affected Amazon OpenSearch Service versions via service software updates. Users are advised to upgrade to these fixed versions or apply the managed service update. Workarounds include restricting write access and avoiding direct access to the vulnerable endpoint. Join the discussion | AWS Security Bulletins | 08/21/2026, 20:12:14 UTC Added: 08/21/2026, 20:20:41 UTC |
0 CVE-2026-75897 is a high-severity vulnerability in OpenSearch Dashboards affecting versions 1.3.0 through 3.7.0 inclusive. It involves improper input validation in the capabilities route handler, which does not limit the size of request payloads. This flaw can be exploited remotely to cause a denial of service (DoS) by sending crafted HTTP requests. The issue is inherited from upstream Kibana versions 7.7.1 through 7.10.2. AWS has released patched service software updates for Amazon OpenSearch Service to address this vulnerability. Join the discussion | CVE Database V5 | 08/20/2026, 21:35:57 UTC Added: 08/18/2026, 17:20:40 UTC |
Showing 1 to 3 of 3 results