Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
0 Pi-hole FTL versions prior to 6.6.1 contain a race condition vulnerability in the HTTP session management subsystem. This flaw was introduced with the version 6.0 rewrite of the embedded CivetWeb-based web server. The vulnerability allows concurrent execution using a shared resource with improper synchronization, potentially leading to high impact on confidentiality, integrity, and availability. The issue has been patched in version 6.6.1. Join the discussion | CVE Database V5 | 06/10/2026, 22:11:29 UTC Added: 06/10/2026, 22:32:03 UTC |
0 Pi-hole FTL is the core engine of the Pi-hole network-level advertisement and tracker blocker. In versions before 6.6.1, the `dns.interface` configuration field in Pi-hole FTL accepted newline characters without validation, allowing an attacker to inject arbitrary directives into the generated dnsmasq configuration file. On installations with no admin password set (the default for many deployments), the configuration API is fully accessible without credentials, allowing a network-adjacent attacker to inject the payload, enable the built-in DHCP server, and achieve arbitrary command execution on the host the next time any device on the network requests a DHCP lease. The injected value is persisted to /etc/pihole/pihole.toml and survives restarts. The strncpy in the code path limits the total interface field to 31 bytes, but payloads such as wlan0\ndhcp-script=/tmp/p fit within this constraint. The dnsmasq config validation introduced in FTL 6.6 only checks syntactic validity, so valid directives injected via newline pass validation successfully. This issue has been fixed in version 6.6.1. Join the discussion | CVE Database V5 | 05/05/2026, 20:50:26 UTC Added: 05/05/2026, 21:23:29 UTC |
0 FTLDNS (pihole-FTL) provides an interactive API and also generates statistics for Pi-hole's Web interface. From 6.0 to before 6.6, the Pi-hole FTL engine contains a Remote Code Execution (RCE) vulnerability in the DHCP hosts configuration parameter (dhcp.hosts). This vulnerability allows an authenticated attacker to inject arbitrary dnsmasq configuration directives through newline characters, ultimately achieving command execution on the underlying system. This vulnerability is fixed in 6.6. Join the discussion | CVE Database V5 | 04/07/2026, 15:20:26 UTC Added: 04/07/2026, 16:01:10 UTC |
0 FTLDNS (pihole-FTL) provides an interactive API and also generates statistics for Pi-hole's Web interface. From 6.0 to before 6.6, the Pi-hole FTL engine contains a Remote Code Execution (RCE) vulnerability in the DHCP lease time configuration parameter (dhcp.leaseTime). This vulnerability allows an authenticated attacker to inject arbitrary dnsmasq configuration directives through newline characters, ultimately achieving command execution on the underlying system. This vulnerability is fixed in 6.6. Join the discussion | CVE Database V5 | 04/07/2026, 15:19:21 UTC Added: 04/07/2026, 16:01:10 UTC |
0 FTLDNS (pihole-FTL) provides an interactive API and also generates statistics for Pi-hole's Web interface. From 6.0 to before 6.6, the Pi-hole FTL engine contains a Remote Code Execution (RCE) vulnerability in the DNS host record configuration parameter (dns.hostRecord). This vulnerability allows an authenticated attacker to inject arbitrary dnsmasq configuration directives through newline characters, ultimately achieving command execution on the underlying system. This vulnerability is fixed in 6.6. Join the discussion | CVE Database V5 | 04/07/2026, 15:18:27 UTC Added: 04/07/2026, 16:01:10 UTC |
0 FTLDNS (pihole-FTL) provides an interactive API and also generates statistics for Pi-hole's Web interface. From 6.0 to before 6.6, the Pi-hole FTL engine contains a Remote Code Execution (RCE) vulnerability in the DNS CNAME records configuration parameter (dns.cnameRecords). This vulnerability allows an authenticated attacker to inject arbitrary dnsmasq configuration directives through newline characters, ultimately achieving command execution on the underlying system. This vulnerability is fixed in 6.6. Join the discussion | CVE Database V5 | 04/07/2026, 15:17:39 UTC Added: 04/07/2026, 15:31:16 UTC |
0 A high-severity remote code execution vulnerability (CVE-2026-35517) exists in Pi-hole FTL versions 6.0 up to but not including 6.6. The vulnerability arises from improper neutralization of special elements in the upstream DNS servers configuration parameter, allowing an authenticated attacker to inject arbitrary dnsmasq configuration directives via newline characters. This injection can lead to command execution on the underlying system. The issue is fixed in version 6.6. No known exploits in the wild have been reported as of the publication date. Join the discussion | CVE Database V5 | 04/07/2026, 15:16:02 UTC Added: 04/07/2026, 15:31:16 UTC |
A vulnerability in Pi-hole FTL versions 6.0 up to before 6.6 allows CLI-scoped API sessions, which are intended to be read-only, to bypass authorization and overwrite configuration via the /api/teleporter endpoint. This occurs because /api/teleporter did not properly restrict Teleporter imports for CLI sessions, unlike /api/config which correctly blocked such mutations. The issue is identified as CWE-863 (Incorrect Authorization) and has a CVSS score of 6.1 (medium severity). The vulnerability is fixed in version 6.6. Join the discussion | CVE Database V5 | 04/07/2026, 15:00:11 UTC Added: 04/07/2026, 15:31:16 UTC |
Showing 1 to 8 of 8 results