Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
NebulaGraph versions up to 3.8.0 expose a runtime configuration HTTP service without any authentication, allowing unauthenticated access to read and modify critical runtime flags. This includes sensitive information such as certificate paths and password files, and enables changing daemon behavior like disabling transport security or altering login attempt limits. The vulnerability has a critical severity with a CVSS score of 9.3. No official patch or remediation guidance is currently available. Join the discussion | CVE Database V5 | 08/26/2026, 15:45:00 UTC Added: 08/26/2026, 15:53:01 UTC |
CVE-2026-74238: Out-of-bounds Read in tier4 nebulaCVE-2026-74238 0 TIER IV Nebula through 1.2.0 contains an out-of-bounds read vulnerability in the Vlp32Decoder::unpack() function that allows unauthenticated remote attackers to cause the decoder to read past the end of a received UDP buffer into adjacent heap memory by sending a short UDP datagram. Attackers can send a malformed datagram to the Velodyne UDP sensor port, which lacks sender-address restrictions present in other drivers, causing fabricated points derived from heap memory contents to be silently published into downstream PointCloud2 messages consumed by Autoware nodes. Join the discussion | CVE Database V5 | 08/17/2026, 18:12:37 UTC Added: 08/17/2026, 18:26:57 UTC |
0 Nebula is a scalable overlay networking tool. In versions from 1.7.0 to 1.10.2, when using P256 certificates (which is not the default configuration), it is possible to evade a blocklist entry created against the fingerprint of a certificate by using ECDSA Signature Malleability to use a copy of the certificate with a different fingerprint. This issue has been patched in version 1.10.3. Join the discussion | CVE Database V5 | 02/06/2026, 22:55:36 UTC Added: 02/06/2026, 23:00:08 UTC |
Slack Nebula before 1.9.7 mishandles CIDR in some configurations and thus accepts arbitrary source IP addresses within the Nebula network. Join the discussion | CVE Database V5 | 10/23/2025, 00:00:00 UTC Added: 10/23/2025, 04:07:02 UTC |
0 An issue was discovered in vesoft NebulaGraph through 3.8.0. It allows bypassing authentication. Join the discussion | CVE Database V5 | 09/22/2024, 00:00:00 UTC Added: 02/25/2026, 21:43:36 UTC |
Showing 1 to 5 of 5 results