Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
0 CVE-2026-53451 is a critical path traversal vulnerability in sgoudelis ground-station prior to version 0.4.13. It allows unauthenticated attackers to write arbitrary files outside the intended directory by exploiting improper pathname limitation in a Socket.IO command. This can lead to remote code execution with service privileges via crafted logging configuration files, and may cause persistent service crashes. The issue is fixed in version 0.4.13. Join the discussion | CVE Database V5 | 08/19/2026, 14:45:23 UTC Added: 08/19/2026, 15:08:59 UTC |
0 CVE-2026-53452 is a path traversal vulnerability in sgoudelis ground-station prior to version 0.4.13. It allows unauthenticated attackers to read arbitrary files outside the intended directory by exploiting improper validation of a pathname used in SDR configuration commands. The vulnerability requires the presence of readable JSON metadata files and associated data files to disclose contents. This issue is fixed in version 0.4.13. Join the discussion | CVE Database V5 | 08/19/2026, 14:44:20 UTC Added: 08/19/2026, 15:08:59 UTC |
0 Ground Station versions prior to 0.6.0 contain an unauthenticated blind server-side request forgery (SSRF) vulnerability. This flaw allows any unauthenticated Socket.IO client to cause the server to issue outbound HTTP requests to attacker-controlled destinations. The vulnerability arises from disabled authentication enforcement, a wildcard CORS policy, and lack of validation on URLs stored and used in scheduled sync tasks. The malicious URL persists in the database and triggers repeated SSRF every 24 hours without requiring attacker presence. Join the discussion | CVE Database V5 | 08/06/2026, 15:38:02 UTC Added: 08/06/2026, 22:13:26 UTC |
0 Ground Station versions prior to 0.6.0 have a high-severity unauthenticated denial-of-service vulnerability in the Socket.IO server. This flaw allows any unauthenticated network peer to send a restart_service command via the service_control event, forcibly terminating the ground-station process. The vulnerability arises from disabled authentication enforcement and a wildcard CORS policy on port 7000, enabling attackers to disrupt satellite-tracking sessions and related services. Repeated exploitation in Docker deployments can cause persistent denial-of-service conditions. Join the discussion | CVE Database V5 | 08/06/2026, 15:19:44 UTC Added: 08/06/2026, 15:41:53 UTC |
Showing 1 to 4 of 4 results