Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
0 CVE-2026-59989 is a critical code injection vulnerability in the Phalcon PHP framework's Volt template engine. In versions 5.15.0 and earlier, the resolveFilter function improperly inserts raw input into generated PHP code without proper sanitization, allowing an attacker who can control Volt template source to inject and execute arbitrary PHP code. This issue is fixed in version 5.16.0. Join the discussion | CVE Database V5 | 08/21/2026, 20:25:44 UTC Added: 08/21/2026, 20:37:40 UTC |
0 Phalcon is a high-performance, full-stack PHP framework. Prior to 5.15.0, every Phalcon MVC application built with a default router registers a built-in route whose compiled PCRE pattern contains the nested quantifier (/.), and the same construct is produced by the /:params placeholder and the CLI router. Phalcon\Mvc\Router::handle() matches this pattern against the attacker-controlled request URI on every request, so a crafted path such as one containing repeated slashes followed by decoded newlines can trigger catastrophic backtracking and cause CPU exhaustion or route-matching failure. This issue is fixed in version 5.15.0. Join the discussion | CVE Database V5 | 07/10/2026, 21:04:26 UTC Added: 07/10/2026, 21:33:03 UTC |
Phalcon is a high-performance, full-stack PHP framework. Prior to 5.14.1, Phalcon\Encryption\Crypt::decrypt compares the attacker-supplied HMAC tag against the freshly computed HMAC using PHP/Zephir identity comparison, which lowers to a byte-wise comparison that returns early on the first differing byte. This observable timing discrepancy can allow an attacker to recover a valid tag byte-by-byte and attach it to a chosen IV and ciphertext so that decrypt() accepts tampered encrypted content as authentic. This issue is fixed in version 5.14.1. Join the discussion | CVE Database V5 | 07/10/2026, 21:02:53 UTC Added: 07/10/2026, 21:33:03 UTC |
Showing 1 to 3 of 3 results