Skip to main content

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Package: pkg:github/sgoudelis/ground-station

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

CVE-2026-53451 is a critical path traversal vulnerability in sgoudelis ground-station prior to version 0.4.13. It allows unauthenticated attackers to write arbitrary files outside the intended directory by exploiting improper pathname limitation in a Socket.IO command. This can lead to remote code execution with service privileges via crafted logging configuration files, and may cause persistent service crashes. The issue is fixed in version 0.4.13.

Join the discussion

CVE-2026-53452 is a path traversal vulnerability in sgoudelis ground-station prior to version 0.4.13. It allows unauthenticated attackers to read arbitrary files outside the intended directory by exploiting improper validation of a pathname used in SDR configuration commands. The vulnerability requires the presence of readable JSON metadata files and associated data files to disclose contents. This issue is fixed in version 0.4.13.

Join the discussion

Ground Station versions prior to 0.6.0 contain an unauthenticated blind server-side request forgery (SSRF) vulnerability. This flaw allows any unauthenticated Socket.IO client to cause the server to issue outbound HTTP requests to attacker-controlled destinations. The vulnerability arises from disabled authentication enforcement, a wildcard CORS policy, and lack of validation on URLs stored and used in scheduled sync tasks. The malicious URL persists in the database and triggers repeated SSRF every 24 hours without requiring attacker presence.

Join the discussion

Ground Station versions prior to 0.6.0 have a high-severity unauthenticated denial-of-service vulnerability in the Socket.IO server. This flaw allows any unauthenticated network peer to send a restart_service command via the service_control event, forcibly terminating the ground-station process. The vulnerability arises from disabled authentication enforcement and a wildcard CORS policy on port 7000, enabling attackers to disrupt satellite-tracking sessions and related services. Repeated exploitation in Docker deployments can cause persistent denial-of-service conditions.

Join the discussion

Showing 1 to 4 of 4 results

Filters:Package: pkg:github/sgoudelis/ground-station
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses