Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
CVE-2026-67200: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in perspective-dev perspectiveCVE-2026-67200 0 Perspective version 5.0.0 and earlier contain a path traversal vulnerability that allows unauthenticated remote attackers to read arbitrary files on the server by including '../' sequences in HTTP request URLs. The vulnerability arises from insufficient sanitization of query strings, enabling traversal outside the intended asset root directory. Sensitive files such as system credentials and application secrets may be exposed. Additionally, a wildcard Access-Control-Allow-Origin header on all responses can expose these results cross-origin. Join the discussion | CVE Database V5 | 08/04/2026, 14:04:39 UTC Added: 08/04/2026, 14:56:55 UTC |
CVE-2026-67199: Allocation of Resources Without Limits or Throttling in perspective-dev perspectiveCVE-2026-67199 0 Perspective 5.0.0 contains a denial of service vulnerability that allows remote attackers to block the server event loop indefinitely by submitting a crafted expression containing unbounded for or while loop constructs in a TableMakeViewReq message. Attackers can embed an arbitrarily large iteration count in an expression column evaluated once per table row, causing the Tornado IOLoop to block without any iteration cap, deadline, or cancellation check, rendering the server unresponsive to all connected clients. Join the discussion | CVE Database V5 | 08/04/2026, 14:04:19 UTC Added: 08/04/2026, 14:56:55 UTC |
CVE-2026-67198: Incomplete Identification of Uploaded File Variables (PHP) in perspective-dev perspectiveCVE-2026-67198 0 Perspective 5.0.0 contains a denial-of-service vulnerability in the VirtualServer protocol dispatcher that allows unauthenticated remote attackers to crash the server process by sending malformed or incomplete protobuf messages. Attackers can send well-formed requests such as ViewToArrowReq with no viewport set or MakeTableReq with no data field to trigger unwrap() calls on None values at nine distinct sites, causing the process to abort with SIGABRT. Join the discussion | CVE Database V5 | 08/04/2026, 14:04:00 UTC Added: 08/04/2026, 14:56:53 UTC |
CVE-2026-67196: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in perspective-dev perspectiveCVE-2026-67196 0 Perspective version 5.0.0 contains a cross-site scripting (XSS) vulnerability in its built-in Debug plugin. This flaw allows attackers to inject arbitrary HTML and JavaScript by writing table cell values with unescaped HTML markup. The vulnerability arises because these values are directly interpolated into innerHTML during CSV serialization rendering without proper escaping. Attackers can exploit this by crafting table rows with payloads that include unquoted attribute injections containing event handler attributes, bypassing RFC 4180 quoting rules. This leads to execution of malicious scripts in the context of the embedding page's origin. Join the discussion | CVE Database V5 | 08/04/2026, 14:03:41 UTC Added: 08/04/2026, 14:56:53 UTC |
CVE-2026-67195: Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') in perspective-dev perspectiveCVE-2026-67195 0 Perspective 5.0.0 contains a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary operating system commands by submitting crafted expression strings to the PolarsVirtualServer backend, which passes client-supplied input directly to Python's eval() with only __builtins__={} cleared. Attackers can exploit Python object attribute traversal through the interpreter's loaded class list to reach subprocess.Popen via a TableValidateExprReq or TableMakeViewReq protobuf message, achieving arbitrary command execution in the Perspective host process. Join the discussion | CVE Database V5 | 08/04/2026, 14:03:17 UTC Added: 08/04/2026, 14:56:53 UTC |
Showing 1 to 5 of 5 results