Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
0 Nuclei is a vulnerability scanner built on a simple YAML-based DSL. From version 3.0.0 to before version 3.8.0, a vulnerability in Nuclei's expression evaluation engine makes it possible for a malicious target server to inject and execute supported DSL expressions. This happens when HTTP response data containing helper/function syntax gets reused by multi-step templates. If the -env-vars / -ev option is explicitly enabled, this can expose host environment variables. That option is off by default, so standard configurations are not affected by the information disclosure risk. This issue has been patched in version 3.8.0. Join the discussion | CVE Database V5 | 05/08/2026, 03:17:19 UTC Added: 05/08/2026, 03:51:25 UTC |
Nuclei versions from 3.0.0 up to but not including 3.8.0 contain an improper access control vulnerability in the JavaScript protocol runtime. This flaw allows JavaScript templates to bypass local file access restrictions and read local . js and . json files via the require() function. The vulnerability is addressed in version 3.8. Join the discussion | CVE Database V5 | 05/08/2026, 03:14:49 UTC Added: 05/08/2026, 03:51:25 UTC |
0 ProjectDiscovery Nuclei 3 before 3.8.0 allows DSL expression injection. This affects use of -env-vars for multi-step templates against untrusted targets (not the default configuration). Join the discussion | CVE Database V5 | 04/20/2026, 07:10:30 UTC Added: 04/20/2026, 07:46:25 UTC |
Showing 1 to 3 of 3 results