Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

CVE-2026-18362: CWE-770 Allocation of resources without limits or throttling in dfir-iris iris-webCVE-2026-18362
0

The IRIS web application version 2.4.26 has a vulnerability where it does not protect user authentication against brute-force attacks. This issue relates to the allocation of resources without limits or throttling, potentially allowing attackers to attempt many authentication requests. The vulnerability has a medium severity with a CVSS score of 5.9. No official patch or remediation has been confirmed yet.

Join the discussion
CVE-2026-18361: CWE-79 Improper neutralization of input during web page generation ('cross-site scripting') in dfir-iris iris-webCVE-2026-18361
0

A stored cross-site scripting (XSS) vulnerability exists in the IRIS web application version 2.4.26, specifically in the datastore upload function. This vulnerability allows an attacker with limited privileges to inject malicious scripts that can execute in the context of other users. The vulnerability is classified as CWE-79 and has a high severity score of 7.6. No official patch or remediation guidance is currently provided by the vendor.

Join the discussion
CVE-2026-18360: CWE-79 Improper neutralization of input during web page generation ('cross-site scripting') in dfir-iris iris-webCVE-2026-18360
0

A stored cross-site scripting (XSS) vulnerability exists in the IRIS web application version 2.4.26 within the custom attributes function. This vulnerability allows an attacker with low privileges and user interaction to inject malicious scripts that can compromise confidentiality and partially impact integrity. The vulnerability has a high severity score of 7.6 and affects version 2.4.26 specifically.

Join the discussion
CVE-2026-16971: CWE-770 Allocation of resources without limits or throttling in dfir-iris iris-webCVE-2026-16971
0

CVE-2026-16971 is a medium severity vulnerability in the dfir-iris iris-web application version 2.4.26. The issue involves the lack of protection for multi-factor authentication (MFA) validation against brute-force attacks, related to allocation of resources without limits or throttling (CWE-770). This could allow an attacker to repeatedly attempt MFA validation without restriction. No official patch or remediation guidance is currently available from the vendor.

Join the discussion
CVE-2026-16970: CWE-613 Insufficient session expiration in dfir-iris iris-webCVE-2026-16970
0

The IRIS web application version 2.4.26 has an ineffective logout functionality that results in insufficient session expiration. This vulnerability allows stolen session cookies to be reused for an extended period, potentially leading to unauthorized access. The CVSS score is 4.2, indicating a medium severity level.

Join the discussion
CVE-2026-16969: CWE-79 Improper neutralization of input during web page generation ('cross-site scripting') in dfir-iris iris-webCVE-2026-16969
0

The IRIS web application version 2.4.26 contains a stored cross-site scripting (XSS) vulnerability in its assets function. This vulnerability allows improper neutralization of input during web page generation, potentially enabling an attacker to execute malicious scripts in the context of the affected application. The vulnerability is classified as CWE-79 and has a high severity rating with a CVSS score of 7.6. No official patch or remediation has been confirmed at this time.

Join the discussion

Showing 1 to 6 of 6 results

Filters:Package: pkg:github/sbaresearch/iris-web
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses