Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
CVE-2026-68750: CWE-407 Inefficient Algorithmic Complexity in rrrene html_sanitize_exCVE-2026-68750 0 CVE-2026-68750 is an inefficient algorithmic complexity vulnerability in the html_sanitize_ex library by rrrene. The vulnerability arises in the traversal engine where processing a large number of sibling elements in sanitized HTML causes quadratic CPU and memory consumption. This can be triggered remotely without authentication by submitting allowed HTML tags with many sibling elements. The issue affects versions from 0.3.1 up to but not including 1.5.3. Join the discussion | CVE Database V5 | 08/06/2026, 14:50:20 UTC Added: 08/06/2026, 15:41:54 UTC |
CVE-2026-68749: CWE-1333 Inefficient Regular Expression Complexity in rrrene html_sanitize_exCVE-2026-68749 0 CVE-2026-68749 is a high-severity vulnerability in the rrrene html_sanitize_ex library affecting versions from 0.3.1 up to but not including 1.5.3. It involves inefficient regular expression complexity in the CSS scrubber component, allowing an unauthenticated remote attacker to cause CPU exhaustion by sending a long CSS declaration in sanitized HTML. The vulnerability results in quadratic processing time due to a regex pattern that retries matching inefficiently on long runs of characters without a colon. The impact is limited to denial of service via CPU resource exhaustion; no data is disclosed or modified. Join the discussion | CVE Database V5 | 08/06/2026, 14:50:12 UTC Added: 08/06/2026, 15:41:54 UTC |
CVE-2026-68747: CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') in rrrene html_sanitize_exCVE-2026-68747 0 CVE-2026-68747 is a low-severity injection vulnerability in the CSS scrubber of the rrrene html_sanitize_ex library. It allows an unauthenticated remote attacker to inject CSS at-rules, such as importing a remote stylesheet, into pages served to other users. The vulnerability arises because the scrubber applies its allowlist only to property:value patterns, leaving other CSS constructs like @import rules uninspected and thus injectable. The injected content remains confined within the <style> element and does not execute scripts. This issue affects versions 0.3.1 up to but not including 1.5.4. Join the discussion | CVE Database V5 | 08/06/2026, 14:50:03 UTC Added: 08/06/2026, 15:41:54 UTC |
CVE-2026-66843: CWE-829 Inclusion of Functionality from Untrusted Control Sphere in rrrene html_sanitize_exCVE-2026-66843 0 CVE-2026-66843 is a low-severity vulnerability in the html_sanitize_ex library (versions 0.3.1 up to but not including 1.5.3). It involves the inclusion of functionality from an untrusted control sphere via the data attribute of an <object> element in sanitized HTML. This allows a remote attacker to load arbitrary documents into a trusted page. However, this does not result in unconditional cross-site scripting due to browser restrictions on javascript: URLs in <object data> and the opaque origin of data: documents. Join the discussion | CVE Database V5 | 08/06/2026, 14:48:20 UTC Added: 08/06/2026, 15:41:54 UTC |
CVE-2026-66829: CWE-601 URL Redirection to Untrusted Site ('Open Redirect') in rrrene html_sanitize_exCVE-2026-66829 0 CVE-2026-66829 is an open redirect vulnerability in the html_sanitize_ex library's HTML5 scrubber. It allows an attacker to inject a <meta http-equiv="refresh"> element in sanitized HTML, causing users to be redirected to an attacker-controlled site. This issue affects versions from 0.3.1 up to but not including 1.5.3. The vulnerability is not a cross-site scripting flaw, as browsers do not execute javascript: URLs in meta refresh elements. The CVSS score is low, indicating limited impact. Join the discussion | CVE Database V5 | 08/06/2026, 14:49:23 UTC Added: 08/06/2026, 15:41:53 UTC |
CVE-2026-66370: CWE-601 URL Redirection to Untrusted Site ('Open Redirect') in rrrene html_sanitize_exCVE-2026-66370 0 CVE-2026-66370 is an open redirect vulnerability in the html_sanitize_ex HTML5 scrubber by rrrene. It allows an unauthenticated remote attacker to manipulate form input elements so that data submitted by a victim is sent to an attacker-controlled external URL. This occurs because the sanitizer does not validate the scheme of URLs in the form and formaction attributes, allowing absolute cross-origin URLs to persist after sanitization. The vulnerability affects versions from 0.3.1 up to but not including 1.5.3. No script execution is possible, and the attacker cannot inject new forms, only retarget existing forms on the page that have an id attribute. Join the discussion | CVE Database V5 | 08/06/2026, 14:49:15 UTC Added: 08/06/2026, 15:41:53 UTC |
Showing 1 to 6 of 6 results