Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
0 An address bar spoofing issue in affected versions of Arc could allow an attacker to spoof the browser address bar via a <select> element that triggers requestFullscreen without displaying the fullscreen notification. Join the discussion | CVE Database V5 | 09/23/2026, 18:55:08 UTC Added: 09/23/2026, 19:03:14 UTC |
0 CVE-2026-48106 is a high-severity vulnerability in Basekick-Labs' Arc, an open SQL-native time-series database. Versions prior to 26.06.1 have a missing authentication mechanism for the MsgReplicateSync payload in the cluster replication receiver, allowing application-layer message tampering or replay attacks despite transport-layer TLS/mTLS protection. The issue is fixed in version 26.06.1. Workarounds include restricting cluster network access, auditing replication logs, or disabling cluster mode until patched. Join the discussion | CVE Database V5 | 08/21/2026, 22:49:12 UTC Added: 08/21/2026, 22:53:19 UTC |
0 CVE-2026-48105 is a path traversal vulnerability in Basekick-Labs' Arc Enterprise time-series database prior to version 26.06.1. The Raft FSM component accepts attacker-controlled file paths without proper validation, allowing potentially unauthorized file access or manipulation. The vulnerability is fixed in version 26.06.1. Mitigations include restricting cluster network access to trusted peers, auditing manifest paths, or disabling cluster mode until patched. Join the discussion | CVE Database V5 | 08/21/2026, 22:47:13 UTC Added: 08/21/2026, 22:53:19 UTC |
0 CVE-2026-47735 is a path traversal vulnerability in Basekick-Labs' Arc time-series database prior to version 26.06.1. The vulnerability arises because Arc's user-SQL validator only blocked certain DuckDB I/O functions via regex denylist, leaving many others unblocked. This allowed unauthorized file access through scalar table functions in SQL queries. The issue is fixed in version 26.06.1 by implementing a structural sandbox at the DuckDB layer that restricts file access to an allowlist and disables further extension installs or loads. Join the discussion | CVE Database V5 | 08/21/2026, 22:42:55 UTC Added: 08/21/2026, 22:53:19 UTC |
0 CVE-2026-48050 is a high-severity vulnerability in Basekick-Labs' Arc time-series database prior to version 26.06.1. The issue arises because the application registers Go's pprof debugging endpoints under /debug/pprof/* without proper authentication, allowing unauthorized access to sensitive profiling information. This exposure occurs due to the authentication middleware bypassing token checks for these endpoints. The vulnerability is patched in version 26.06.1. Workarounds include blocking access to /debug/pprof* at the reverse proxy or load balancer, restricting API port access via firewall rules, or disabling the pprof handler in the source code and rebuilding the application. Join the discussion | CVE Database V5 | 08/21/2026, 22:40:12 UTC Added: 08/21/2026, 22:53:19 UTC |
Showing 1 to 5 of 5 results