Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
In Splunk SOAR versions below 8.6.0, users with the OnPrem Broker role can write files outside the intended Automation Broker log directory due to insufficient validation of filenames during log uploads. This vulnerability allows limited unauthorized file write capabilities but does not impact confidentiality or availability. The issue is identified as CWE-22 (Path Traversal). Join the discussion | GCVE Database | 08/20/2026, 00:35:03 UTC Added: 08/20/2026, 14:09:12 UTC |
Splunk SOAR versions below 8.6.0 contain a vulnerability where an authenticated user with restricted tenant access can use the REST API to view tenant names and identifiers outside their role scope. This occurs because role-based tenant restrictions are not enforced properly in multi-tenant deployments when returning tenant information via the REST API. Join the discussion | GCVE Database | 08/20/2026, 00:35:03 UTC Added: 08/20/2026, 14:09:12 UTC |
Splunk SOAR versions below 8.6.0 contain a stored Cross-Site Scripting (XSS) vulnerability that allows a user with the "Incident Commander" role to store JavaScript in a note. This script can execute in the browser of another user when they open the note. The vulnerability arises because note content is treated as HTML without proper sanitization when the note format changes. Exploitation requires tricking the victim into initiating a request in their browser. The vulnerability has a moderate severity score and no known exploits in the wild. Join the discussion | GCVE Database | 08/20/2026, 00:35:02 UTC Added: 08/20/2026, 14:09:12 UTC |
In Splunk SOAR versions below 8.6.0, a user who holds the "Automation Engineer" Splunk SOAR role could run arbitrary Structured Query Language (SQL) statements against the Splunk SOAR database through custom list retrieval in a playbook, allowing for create, read, update, and delete operations on all relevant data stored in the Splunk SOAR database. The SQL injection is possible because Splunk SOAR builds the custom list database lookup with the supplied list name instead of a bound SQL value. For more information see Manage roles and permissions in Splunk SOAR (https://help.splunk.com/en/splunk-soar/soar-cloud/administer-soar-cloud/manage-your-splunk-soar-cloud-users-and-accounts/manage-roles-and-permissions-in-splunk-soar-cloud) and Create custom lists for use in Splunk SOAR playbook comparisons (https://help.splunk.com/en/splunk-soar/soar-cloud/build-playbooks/manage-playbooks-and-playbook-settings/create-custom-lists-for-use-in-splunk-soar-cloud-playbook-comparisons) in the Splunk documentation. Join the discussion | GCVE Database | 08/19/2026, 21:34:54 UTC Added: 08/20/2026, 14:09:15 UTC |
0 CVE-2026-76362 affects Splunk SOAR versions below 8.6.0. The vulnerability arises because the CyberArk REST client integrated with Splunk SOAR does not validate server certificates by default. An unauthenticated attacker with network interception capabilities between Splunk SOAR and the CyberArk REST server could access or modify sensitive data exchanged through the credential manager. This flaw requires the attacker to be able to observe or alter network traffic. The vulnerability has a high severity rating with a CVSS score of 7.4. Join the discussion | CVE Database V5 | 08/19/2026, 21:34:52 UTC Added: 08/19/2026, 21:38:35 UTC |
CVE-2026-76361 is a Server-Side Request Forgery (SSRF) vulnerability in Splunk SOAR versions prior to 8.6.0. An administrator user can exploit the /rest/support/connectivity/.../check_connectivity endpoint to make the server initiate outbound network connections to arbitrary destinations without sufficient validation. This allows the attacker to probe internal hosts and ports for reachability. The vulnerability has a low severity score and does not impact confidentiality, integrity, or availability beyond limited information disclosure about network reachability. Join the discussion | CVE Database V5 | 08/19/2026, 21:34:51 UTC Added: 08/19/2026, 21:38:35 UTC |
0 An issue was discovered in Logpoint before 7.5.0. SOAR uses a static JWT secret key to generate tokens that allow access to SOAR API endpoints without authentication. This static key vulnerability enables attackers to create custom JWT secret keys for unauthorized access to these endpoints. Join the discussion | CVE Database V5 | 11/07/2024, 00:00:00 UTC Added: 02/25/2026, 21:37:00 UTC |
Showing 1 to 7 of 7 results