Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
Devolutions Server versions 2026.2.16 and earlier have an improper certificate validation vulnerability on LDAPS connections to Active Directory. This flaw allows a network-positioned attacker to intercept privileged directory service credentials by presenting a spoofed domain controller certificate. Join the discussion | GCVE Database | 09/15/2026, 21:31:25 UTC Added: 09/16/2026, 03:07:20 UTC |
A Server-Side Request Forgery (SSRF) vulnerability exists in the VMware synchronization feature of Devolutions Server versions 2026.2.16 and earlier. This flaw allows a low-privileged authenticated user to access other users' credentials and reach internal or cloud-metadata network endpoints by submitting a crafted connection definition for datacenter discovery. Join the discussion | GCVE Database | 09/15/2026, 21:31:24 UTC Added: 09/16/2026, 03:07:21 UTC |
An improper access control vulnerability exists in the vault entry listing feature of Devolutions Server versions 2026.2.16 and earlier. This flaw allows an authenticated user without the view-password permission to retrieve cleartext passwords by sending a specially crafted request to the entry listing endpoint with password disclosure parameters. Join the discussion | GCVE Database | 09/15/2026, 21:31:24 UTC Added: 09/16/2026, 03:07:21 UTC |
Devolutions Server versions 2026.2.16 and earlier contain an improper certificate validation vulnerability in the shared HTTP client used by synchronization and integration features. This flaw allows a network-positioned attacker to intercept and modify outbound TLS connections by presenting a spoofed or self-signed certificate. Join the discussion | GCVE Database | 09/15/2026, 21:31:24 UTC Added: 09/16/2026, 03:07:21 UTC |
Improper certificate validation on LDAPS connections to Active Directory in Devolutions Server 2026.2.16 and earlier allows a network-positioned attacker to intercept privileged directory service credentials via a spoofed domain controller certificate. Join the discussion | CVE Database V5 | 09/15/2026, 19:14:33 UTC Added: 09/15/2026, 19:32:06 UTC |
CVE-2026-84850 is a vulnerability in Devolutions Server versions up to 2026.2.16 that involves improper certificate validation in the shared HTTP client used by synchronization and integration features. This flaw allows a network-positioned attacker to intercept and tamper with outbound TLS connections by presenting a spoofed or self-signed certificate. Join the discussion | CVE Database V5 | 09/15/2026, 19:11:12 UTC Added: 09/15/2026, 22:11:46 UTC |
CVE-2026-90969 is an improper access control vulnerability in Devolutions Server versions up to 2026.2.16. It allows an authenticated user without the view-password permission to retrieve cleartext passwords by exploiting the vault entry listing feature with specific request parameters. Join the discussion | CVE Database V5 | 09/15/2026, 19:09:33 UTC Added: 09/15/2026, 22:11:46 UTC |
CVE-2026-90971 is an authorization vulnerability in Devolutions Server affecting versions up to 2026.2.16. It allows a low-privileged authenticated user to exploit the VMware synchronization feature to perform Server-Side Request Forgery (SSRF). This enables the attacker to access other users' credentials and reach internal or cloud-metadata network endpoints by submitting a crafted connection definition for datacenter discovery. Join the discussion | CVE Database V5 | 09/15/2026, 19:07:02 UTC Added: 09/15/2026, 22:11:46 UTC |
Laci Synchroni is a decentralized mod and appearance sync server and plugin for Dalamud. Versions of the backend prior to 1.2.3 have an improper authentication vulnerability in the application's OAuth2 login flow. The application relies on client-side state by trusting the `UID` field inside the `Authentications` object of a user's local `config.json` file. By manually editing this local file on their PC prior to logging in, a user can supply an arbitrary UID. Because the server fails to validate that the authenticated OAuth2 identity matches the requested UID, an attacker can fully impersonate any target user and perform actions on their behalf. This issue has been resolved in version 1.2.3. The patch modifies `AuthorizeOauthAsync` inside the `SecretKeyAuthenticatorService` to strictly bind the lookup of the requested User ID (`requestedUid`) to the record of the successfully authenticated identity (`primaryUid`). The server will no longer load or return session tokens for a requested UID unless it matches the verified, authenticated database record. No known workarounds are available. Join the discussion | CVE Database V5 | 09/11/2026, 16:23:48 UTC Added: 09/11/2026, 16:32:32 UTC |
Bulletin ID: 2026-006-AWS Scope: AWS Content Type: Informational Publication Date: 2026/03/03 10:15 AM PST Description: Amazon RDS/Aurora is a managed relational database service. We identified CVE-2026-3494. In MariaDB server version through 11.8.5, when server audit plugin is enabled with server_audit_events variable configured with QUERY_DCL, QUERY_DDL, or QUERY_DML filtering, if an authenticated database user invokes a SQL statement prefixed with double-hyphen (‐‐) or hash (#) style comments, the statement is not logged. Impacted versions: - MariaDB Server (10.6.24 and prior, 10.11.15 and prior, 11.4.9 and prior, and 11.8.5 and prior) - Amazon Aurora MySQL (2.12.5 and prior, 3.01.0 to 3.04.5, 3.05.1 to 3.10.2, and 3.11.0) - Amazon RDS for MySQL (5.7.44-RDS.20251212 and prior, 8.0.11 to 8.0.44, and 8.4.3 to 8.4.7) - Amazon RDS for MariaDB (10.6.24 and prior, 10.11.4 to 10.11.15, 11.4.3 to 11.4.9, and 11.8.3 to 11.8.5) Please refer to the article below for the most up-to-date and complete information related to this AWS Security Bulletin. Join the discussion | CVE Database V5 | 08/20/2026, 21:35:57 UTC Added: 03/03/2026, 18:33:21 UTC |
Showing 1 to 10 of 68 results