Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
CVE-2026-70464: CWE-770 Allocation of Resources Without Limits or Throttling in RsyncProject rsyncCVE-2026-70464 0 rsync daemon 2.0.0 before 3.5.0 contains a denial of service vulnerability that allows unauthenticated remote attackers to exhaust daemon connection slots by stalling the handshake process before or after module selection without triggering the I/O timeout. Attackers can open many simultaneous connections and trickle data at the minimum rate to avoid timeout, or stall entirely before module selection where no timeout applies, consuming all available connection slots and denying service to legitimate clients. Join the discussion | CVE Database V5 | 08/13/2026, 14:41:47 UTC Added: 08/13/2026, 15:12:13 UTC |
CVE-2026-70463: CWE-863 Incorrect Authorization in RsyncProject rsyncCVE-2026-70463 0 rsync 3.1.0 before 3.5.0 contains an authorization bypass in auth users directive parsing. The auth users parser uses comma-only tokenization when splitting the user list, which fails to correctly handle entries of the form @Group Name where the group name contains a space. The space within the group name causes the parser to split the entry at the space boundary, discarding the deny rule associated with the group. An authenticated user whose username or group membership would be denied by an @Group Name auth users entry can connect to a restricted module because the deny rule is silently discarded during parsing. Join the discussion | CVE Database V5 | 08/13/2026, 14:42:07 UTC Added: 08/13/2026, 15:12:10 UTC |
CVE-2026-70462: CWE-190 Integer Overflow or Wraparound in RsyncProject rsyncCVE-2026-70462 0 rsync 3.1.0 before 3.5.0 contains a signed integer overflow vulnerability in the I/O timeout implementation that allows attackers to permanently disable connection timeouts by injecting MSG_IO_TIMEOUT messages carrying non-positive (zero or negative) values. Attackers can craft malicious MSG_IO_TIMEOUT messages that cause the timeout variable to wrap to a non-positive value, preventing the timeout check from firing and enabling idle or stalled connections to hold daemon slots indefinitely, leading to resource exhaustion. Join the discussion | CVE Database V5 | 08/13/2026, 14:42:28 UTC Added: 08/13/2026, 15:12:10 UTC |
CVE-2026-70461: CWE-787 Out-of-bounds Write in RsyncProject rsyncCVE-2026-70461 0 rsync 3.2.5 before 3.5.0 contains a heap out-of-bounds write vulnerability that allows remote unauthenticated attackers to write one attacker-controlled byte past the end of a heap allocation by supplying a crafted files-from entry. Attackers can trigger the vulnerability against a read-only rsync daemon module by providing a files-from entry containing both an interior and trailing backslash, causing the add_implied_include() function to under-count the trailing backslash when sizing the destination buffer. Join the discussion | CVE Database V5 | 08/13/2026, 14:42:49 UTC Added: 08/13/2026, 15:12:10 UTC |
CVE-2026-70460: CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in RsyncProject rsyncCVE-2026-70460 0 rsync 2.3.3 before 3.5.0 contains a path traversal vulnerability that allows a malicious sender to escape the module root by exploiting symlinks within the module file tree when using --partial-dir or --backup-dir options. Attackers with write access to place a symlink under the module root, or who can exploit a pre-existing trusted symlink, can direct file writes to locations outside the intended module root, achieving arbitrary file write relative to the module root parent. Join the discussion | CVE Database V5 | 08/13/2026, 14:43:06 UTC Added: 08/13/2026, 15:12:10 UTC |
CVE-2026-70459: CWE-908 Use of Uninitialized Resource in RsyncProject rsyncCVE-2026-70459 0 rsync 3.0.0 before 3.5.0 contains a null pointer dereference vulnerability in the daemon child process that allows remote attackers to crash the daemon by sending a file list whose first entry is a dot entry not typed as a directory. The daemon dereferences the first file list entry as a directory structure pointer without verifying the entry type, resulting in an invalid or uninitialized pointer dereference that terminates the client connection. Join the discussion | CVE Database V5 | 08/13/2026, 14:43:32 UTC Added: 08/13/2026, 15:12:10 UTC |
CVE-2026-70458: CWE-787 Out-of-bounds Write in RsyncProject rsyncCVE-2026-70458 0 rsync 3.0.0 before 3.5.0 contains an out-of-bounds write vulnerability that allows attackers to corrupt memory by triggering HLINK_BUMP processing on file entries with the FLAG_HLINKED flag set while the hard-link preservation option is inactive. Attackers can exploit the missing F_SUM field in the file_struct layout to access memory past the end of the allocated structure, corrupting adjacent heap or stack data. Join the discussion | CVE Database V5 | 08/13/2026, 14:44:06 UTC Added: 08/13/2026, 15:12:10 UTC |
CVE-2026-70457: CWE-131 Incorrect Calculation of Buffer Size in RsyncProject rsyncCVE-2026-70457 0 rsync 3.2.3 before 3.5.0 contains an out-of-bounds write in parse_size_arg() where the return value of snprintf() is used directly as an index into a .bss-segment array without bounds checking. When snprintf truncates the formatted size string, the return value equals the number of characters that would have been written including the truncated portion, and this value may exceed the array length. The subsequent indexed write targets memory outside the intended array bounds, corrupting .bss memory. Join the discussion | CVE Database V5 | 08/13/2026, 14:44:30 UTC Added: 08/13/2026, 15:12:10 UTC |
CVE-2026-70456: CWE-787 Out-of-bounds Write in RsyncProject rsyncCVE-2026-70456 0 rsync 3.0.1 before 3.5.0 contains an out-of-bounds write vulnerability in the read_args() function that allows a malicious sender to corrupt adjacent heap memory by sending a crafted argument list. When the argument count causes the argv allocation to be exactly full, the trailing NULL terminator is written one slot beyond the allocation boundary, corrupting adjacent heap memory. Join the discussion | CVE Database V5 | 08/13/2026, 14:44:56 UTC Added: 08/13/2026, 15:12:10 UTC |
CVE-2026-70455: CWE-770 Allocation of Resources Without Limits or Throttling in RsyncProject rsyncCVE-2026-70455 0 rsync 3.4.2 before 3.5.0 contains a denial of service vulnerability that allows a remote sender to exhaust system resources by specifying the --zt short alias for --compress-threads, which bypasses the refuse options directive's string matching on long option names. Attackers can specify --zt=N with a large value to spawn an unbounded number of Zstandard worker threads on the receiver, exhausting available thread and memory resources. Join the discussion | CVE Database V5 | 08/13/2026, 14:45:11 UTC Added: 08/13/2026, 15:12:10 UTC |
Showing 1 to 10 of 37 results