Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
A vulnerability in Sipeed PicoClaw up to version 0.2.9 allows authentication bypass via manipulation of the argument allowed_cidrs in the First Run Setup component. The issue exists in the file web/backend/middleware/access_control.go. The attack can be initiated remotely but has high complexity and is difficult to exploit. A patch identified by commit 017601354be38cb027ff3ffb01aed79bd5d12610 is recommended to fix this issue. Join the discussion | GCVE Database | 07/19/2026, 00:30:23 UTC Added: 07/19/2026, 03:41:47 UTC |
A vulnerability was detected in Sipeed PicoClaw up to 0.2.9. The impacted element is an unknown function of the file web/backend/middleware/access_control.go of the component First Run Setup. Performing a manipulation of the argument allowed_cidrs results in authentication bypass using alternate channel. The attack may be initiated remotely. The attack's complexity is rated as high. The exploitability is regarded as difficult. The exploit is now public and may be used. The patch is named 017601354be38cb027ff3ffb01aed79bd5d12610. Applying a patch is the recommended action to fix this issue. Join the discussion | CVE Database V5 | 07/18/2026, 23:30:18 UTC Added: 07/18/2026, 23:57:32 UTC |
CVE-2026-16197: Missing Authorization in Sipeed PicoClawCVE-2026-16197 0 A security vulnerability has been detected in Sipeed PicoClaw up to 0.2.9. The affected element is the function handleMessageReceive of the file pkg/channels/feishu/feishu_64.go of the component Group Message Handler. Such manipulation leads to missing authorization. The attack can be launched remotely. The exploit has been disclosed publicly and may be used. The reported GitHub issue was closed automatically due to inactivity. Join the discussion | CVE Database V5 | 07/18/2026, 23:00:12 UTC Added: 07/18/2026, 23:12:19 UTC |
A time-of-check to time-of-use (TOCTOU) vulnerability exists in Sipeed PicoClaw up to version 0.2.9, specifically in the ExecTool.executeRun function in pkg/agent/pipeline_execute.go. The vulnerability arises from manipulation of the argument 'cwe'. Exploitation requires local access. The issue was publicly reported but marked as 'not planned' for a fix. No patch or official remediation is currently available. The vulnerability is rated as low severity. Join the discussion | GCVE Database | 07/18/2026, 09:32:17 UTC Added: 07/18/2026, 19:25:18 UTC |
A security flaw has been discovered in Sipeed PicoClaw up to 0.2.9. This affects the function webhook.ParseRequest of the file pkg/channels/line/line.go of the component LINE Webhook. The manipulation results in authentication bypass by capture-replay. The attack may be launched remotely. The exploit has been released to the public and may be used for attacks. The reported GitHub issue was closed automatically with the label "not planned" by a bot. Join the discussion | CVE Database V5 | 07/18/2026, 08:30:09 UTC Added: 07/18/2026, 08:57:48 UTC |
0 A vulnerability was identified in Sipeed PicoClaw up to 0.2.9. The impacted element is the function ExecTool.executeRun of the file pkg/agent/pipeline_execute.go. The manipulation of the argument cwe leads to time-of-check time-of-use. The attack must be carried out locally. The exploit is publicly available and might be used. The reported GitHub issue was closed automatically with the label "not planned" by a bot. Join the discussion | CVE Database V5 | 07/18/2026, 08:15:07 UTC Added: 07/18/2026, 08:57:48 UTC |
A vulnerability was determined in Sipeed PicoClaw up to 0.2.9. The affected element is an unknown function of the file web/backend/api/auth.go. Executing a manipulation can lead to cross-site request forgery. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized. This patch is called 4b0229351678f479429b8d8b19207757266f246b. Applying a patch is advised to resolve this issue. Join the discussion | GCVE Database | 07/18/2026, 07:45:09 UTC Added: 07/18/2026, 19:25:16 UTC |
A vulnerability was determined in Sipeed PicoClaw up to 0.2.9. The affected element is an unknown function of the file web/backend/api/auth.go. Executing a manipulation can lead to cross-site request forgery. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized. This patch is called 4b0229351678f479429b8d8b19207757266f246b. Applying a patch is advised to resolve this issue. Join the discussion | CVE Database V5 | 07/18/2026, 07:45:09 UTC Added: 07/18/2026, 08:57:48 UTC |
0 A security vulnerability has been detected in Sipeed PicoClaw up to 0.2.9. This affects the function IPAllowlist of the file web/backend/middleware/access_control.go of the component Launcher. Such manipulation leads to improper access controls. The attack may be performed from remote. The exploit has been disclosed publicly and may be used. The name of the patch is 3126. A patch should be applied to remediate this issue. Join the discussion | CVE Database V5 | 07/10/2026, 01:45:08 UTC Added: 07/10/2026, 02:33:15 UTC |
0 A weakness has been identified in Sipeed PicoClaw up to 0.2.9. Affected by this issue is some unknown functionality of the file pkg/channels/mqtt/mqtt.go of the component MQTT Channel Handler. This manipulation of the argument client_id causes incorrect authorization. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used for attacks. The reported GitHub issue was closed automatically due to inactivity. Join the discussion | CVE Database V5 | 07/10/2026, 01:30:09 UTC Added: 07/10/2026, 01:48:04 UTC |
Showing 1 to 10 of 13 results