Skip to main content

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Package: pkg:github/opensearch-project/opensearch-dashboards

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

CVE-2026-84942 is a high-severity cross-site scripting (XSS) vulnerability in AWS Amazon OpenSearch Service affecting the Vega expression function implementation in OpenSearch Dashboards. It allows a remote authenticated user with dashboard write permissions to execute arbitrary JavaScript in other users' browsers by saving a specially crafted Vega visualization. The vulnerability arises because the input validation routine failed to properly inspect nested arrays, allowing malicious function properties to bypass checks. This can lead to complete compromise of user sessions without impacting availability.

Join the discussion

CVE-2026-77811 is a stored cross-site scripting (XSS) vulnerability in the dashboards-observability plugin of OpenSearch Dashboards. It allows a remote authenticated user with write permissions to upload a custom integration containing arbitrary JavaScript. When other users access the affected static file endpoint, the malicious script executes in their browser, potentially performing actions on their behalf with their privileges. This affects self-managed OpenSearch Dashboards versions before 3.4 and 2.19.6, and Amazon OpenSearch Service versions before 3.3. The issue has been fixed in OpenSearch Dashboards versions 3.4 and 2.19.6 and all affected Amazon OpenSearch Service versions via service software updates. Users are advised to upgrade to these fixed versions or apply the managed service update. Workarounds include restricting write access and avoiding direct access to the vulnerable endpoint.

Join the discussion

CVE-2026-75897 is a high-severity vulnerability in OpenSearch Dashboards affecting versions 1.3.0 through 3.7.0 inclusive. It involves improper input validation in the capabilities route handler, which does not limit the size of request payloads. This flaw can be exploited remotely to cause a denial of service (DoS) by sending crafted HTTP requests. The issue is inherited from upstream Kibana versions 7.7.1 through 7.10.2. AWS has released patched service software updates for Amazon OpenSearch Service to address this vulnerability.

Join the discussion

Showing 1 to 3 of 3 results

Filters:Package: pkg:github/opensearch-project/opensearch-dashboards
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses