Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
CVE-2026-62355: CWE-269: Improper Privilege Management in taosdata TDengineCVE-2026-62355 0 TDengine is an open source, time-series database optimized for Internet of Things devices. Prior to 3.4.1.15, a Data Reader admin_user on a TDengine Cloud DB instance could run create udf even though standard users should have read-only permissions for non-database objects and show dnodes and create user were denied. This issue is fixed in version 3.4.1.15. Join the discussion | CVE Database V5 | 07/15/2026, 18:51:50 UTC Added: 07/15/2026, 19:18:11 UTC |
CVE-2026-62353: CWE-125: Out-of-bounds Read in taosdata TDengineCVE-2026-62353 0 TDengine is a time-series database optimized for Internet of Things devices. Prior to 3.4.1.14, source/libs/parser/src/parTokenizer.c tGetToken() incremented past a trailing backslash in a SQL string literal such as 'abc\ and read one byte beyond the null terminator, allowing an authenticated user who can submit SQL queries to crash the server and possibly leak adjacent memory. This issue is fixed in version 3.4.1.14. Join the discussion | CVE Database V5 | 07/15/2026, 19:08:55 UTC Added: 07/15/2026, 19:18:11 UTC |
CVE-2026-62351: CWE-125: Out-of-bounds Read in taosdata TDengineCVE-2026-62351 0 TDengine is a time-series database optimized for Internet of Things devices. Prior to 3.4.1.15, source/libs/transport/src/transComm.c transDecompressMsg() read STransCompMsg.contLen when pHead->comp == 1 without first validating that the RPC packet contained the 8-byte STransCompMsg structure, causing an unauthenticated out-of-bounds read, uncontrolled allocation, integer underflow, and server crash. This issue is fixed in version 3.4.1.15. Join the discussion | CVE Database V5 | 07/15/2026, 19:08:06 UTC Added: 07/15/2026, 19:18:11 UTC |
CVE-2026-62350: CWE-94: Improper Control of Generation of Code ('Code Injection') in taosdata TDengineCVE-2026-62350 0 TDengine is an open source, time-series database optimized for Internet of Things devices. Prior to 3.4.1.15, a user with create udf privilege could upload a crafted shared library and install it as a user-defined function, such as eval, then execute arbitrary C code on the TDengine server side through database queries. This issue is fixed in version 3.4.1.15. Join the discussion | CVE Database V5 | 07/15/2026, 18:54:26 UTC Added: 07/15/2026, 19:18:11 UTC |
CVE-2026-62349: CWE-121: Stack-based Buffer Overflow in taosdata TDengineCVE-2026-62349 0 TDengine is an open source, time-series database optimized for Internet of Things devices. In 3.4.1.6 and earlier, source/libs/parser/src/parUtil.c trimString() checks space for only one byte before processing SQL string escape sequences \%, \_, or \x, allowing a one-byte out-of-bounds write to the stack buffer tmpTokenBuf that can cause denial of service and potentially remote code execution. This issue is fixed in version 3.4.1.14. Join the discussion | CVE Database V5 | 07/15/2026, 18:55:07 UTC Added: 07/15/2026, 19:18:11 UTC |
CVE-2026-62348: CWE-862: Missing Authorization in taosdata TDengineCVE-2026-62348 0 A missing authorization vulnerability exists in TDengine Enterprise prior to version 3.4.1.15. An authenticated low-privilege SQL user could execute the KILL SSMIGRATE <id> command against an active shared-storage migration due to a commented-out privilege check. This issue allows unauthorized interruption of migration processes. The vulnerability is fixed in version 3.4.1.15. Join the discussion | CVE Database V5 | 07/15/2026, 19:07:07 UTC Added: 07/15/2026, 19:18:11 UTC |
Showing 1 to 6 of 6 results