Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
0 OpenStack Ironic through 38.0.0 may send a username and password to an unexpected remote host when Image Service is configured for HTTP(S) Basic Authentication. Join the discussion | CVE Database V5 | 09/11/2026, 21:32:33 UTC Added: 09/11/2026, 21:50:28 UTC |
0 In OpenStack Ironic before 38.0.1, the autodetect deploy interface may fail to run cleaning immediately after enrollment with, or changing to, the autodetect deploy interface. Join the discussion | CVE Database V5 | 08/14/2026, 22:53:18 UTC Added: 08/14/2026, 22:57:12 UTC |
CVE-2026-71201 is an authorization vulnerability in OpenStack Ironic up to version 38.0.0. It allows a project reader with limited privileges to craft a request that returns Portgroups assigned to Nodes owned or leased by other projects. The vulnerability has a medium severity with a CVSS score of 5. No official patch or remediation information is currently available. Join the discussion | CVE Database V5 | 08/05/2026, 06:19:33 UTC Added: 08/05/2026, 06:26:59 UTC |
In OpenStack Ironic before 37.0.1, an Ironic user with the ability to deploy nodes using the IPMI management interface can maliciously use the send_raw step to send arbitrary IPMI commands to a node, bypassing Ironic's access control. Join the discussion | CVE Database V5 | 07/10/2026, 03:10:54 UTC Added: 07/10/2026, 03:48:18 UTC |
OpenStack Ironic through before 37.0.1 allows creation or modification of nodes cross-project without authorization. Join the discussion | CVE Database V5 | 07/10/2026, 00:00:00 UTC Added: 07/10/2026, 03:48:18 UTC |
0 In OpenStack Ironic 32 before 37.0.0, an unauthenticated malicious user could submit a crafted JSON string to some endpoints on the API or JSON-RPC service and effect a service crash. Join the discussion | CVE Database V5 | 06/04/2026, 23:59:20 UTC Added: 06/05/2026, 19:52:31 UTC |
In OpenStack Ironic through 35.x before a3f6d73, during image handling, an infinite loop in checksum calculations can occur via the file:///dev/zero URL. Join the discussion | CVE Database V5 | 05/14/2026, 00:00:00 UTC Added: 05/14/2026, 04:06:35 UTC |
0 OpenStack Ironic before 35.0.1 allows ipmitool execution in a non-default configuration that has a console interface. Join the discussion | CVE Database V5 | 04/28/2026, 04:53:10 UTC Added: 04/28/2026, 05:22:01 UTC |
0 In OpenStack Ironic before 21.4.4, 22.x and 23.x before 23.0.3, 23.x and 24.x before 24.1.3, and 25.x and 26.x before 26.1.0, there is a lack of checksum validation of supplied image_source URLs when configured to convert images to a raw format for streaming. Join the discussion | CVE Database V5 | 10/04/2024, 00:00:00 UTC Added: 02/25/2026, 21:43:36 UTC |
Showing 1 to 9 of 9 results