Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
0 CVE-2026-41451 is a command injection vulnerability in tclahr's UAC (Unix-like Artifacts Collector) versions prior to 3.3.0. The flaw exists in the parse_artifact.sh script where usernames and home directory paths from /etc/passwd are directly substituted into commands without proper escaping before being executed via eval. This allows attackers to inject shell metacharacters through crafted /etc/passwd entries, potentially leading to arbitrary command execution on the analyst's host system. Join the discussion | CVE Database V5 | 08/21/2026, 17:36:02 UTC Added: 08/21/2026, 17:52:43 UTC |
0 UAC (Unix-like Artifacts Collector) versions prior to 3.3.0 contain a command injection vulnerability in the _command_collector function where foreach command output lines are substituted directly into command strings via sed without proper escaping before being evaluated with eval. Attackers can exploit this by crafting malicious filenames or artifact definitions containing shell metacharacters such as command substitution syntax or semicolons to execute arbitrary commands on the analyst's host system. Join the discussion | CVE Database V5 | 08/21/2026, 17:35:04 UTC Added: 08/21/2026, 17:52:43 UTC |
0 UAC (Unix-like Artifacts Collector) versions prior to 3.3.0 contain a command injection vulnerability in the _run_command function that allows attackers to execute arbitrary commands by injecting shell metacharacters into untrusted data such as usernames, process names, or filenames. Attackers can exploit this vulnerability through crafted evidence inputs, mounted images with hostile filenames, or tampered artifact definitions to achieve remote code execution on the analyst's host when processing evidence. Join the discussion | CVE Database V5 | 08/21/2026, 17:33:50 UTC Added: 08/21/2026, 17:52:43 UTC |
0 UAC (Unix-like Artifacts Collector) before 3.3.0-rc1 contains a command injection vulnerability in the placeholder substitution and command execution pipeline where the _run_command() function passes constructed command strings directly to eval without proper sanitization. Attackers can inject shell metacharacters or command substitutions through attacker-controlled inputs including %line% values from foreach iterators and %user% / %user_home% values derived from system files to achieve arbitrary command execution with the privileges of the UAC process. Join the discussion | CVE Database V5 | 04/08/2026, 21:35:27 UTC Added: 04/08/2026, 21:50:49 UTC |
Showing 1 to 4 of 4 results