Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
A vulnerability in Tor before version 0.4.9.12 allows remote attackers to cause a denial of service by triggering a crash. This occurs because Tor interprets the CC_RESPONSE extension even when the CC_REQUEST extension was not sent, leading to corrupted congestion-control state. Join the discussion | CVE Database V5 | 09/09/2026, 01:29:46 UTC Added: 09/09/2026, 01:37:43 UTC |
CVE-2026-77584 is a high-severity vulnerability in Tor before version 0.4.9.10 involving incorrect synchronization. The flaw allows a malicious client to send a RELAY_COMMAND_BEGIN before a CONFLUX_LINK on the same circuit, causing an exit stream to become orphaned and leading to a use-after-free condition when the circuit is freed. This can impact the integrity and availability of the Tor process. Join the discussion | CVE Database V5 | 08/24/2026, 00:00:00 UTC Added: 08/20/2026, 20:52:50 UTC |
CVE-2026-77642 is an out-of-bounds write vulnerability in Tor versions before 0.4.9.9. It occurs when parsing a consensus or detached signature with an unexpected signature digest type. The impact is generally minor for most Tor roles but can be significant for directory authorities. This vulnerability has a CVSS score of 7.5, indicating high severity. Join the discussion | CVE Database V5 | 08/20/2026, 22:18:00 UTC Added: 08/20/2026, 21:37:42 UTC |
A vulnerability in Tor versions before 0.4.9.9 allows an attacker to bypass the compression bomb detection by concatenating multiple gzip or zlib sub-streams, each below the detection threshold. This flaw can lead to denial of service by causing resource exhaustion. The issue is tracked as CVE-2026-77639 and is classified under CWE-420 (Unprotected Alternate Channel). Join the discussion | CVE Database V5 | 08/20/2026, 22:00:00 UTC Added: 08/20/2026, 21:07:38 UTC |
A vulnerability in Tor versions before 0.4.9.9 allows a NULL write after free due to unchecked return values when sending a CONFLUX_SWITCH cell fails. This can cause a crash by writing to freed memory. Join the discussion | CVE Database V5 | 08/20/2026, 21:17:00 UTC Added: 08/20/2026, 21:22:39 UTC |
0 A vulnerability in Tor before version 0.4.9.9 causes an infinite loop when decompressing a truncated zlib/gzip stream with done=1. The issue arises because the decompression never reaches the expected end state, leading to a retry loop. This flaw was fixed by returning an error to allow clean aborting of the operation. Join the discussion | CVE Database V5 | 08/20/2026, 21:17:00 UTC Added: 08/20/2026, 21:07:38 UTC |
0 A race condition vulnerability (CWE-362) exists in Tor versions from 0.3.5.3-alpha up to but not including 0.4.9.11. This flaw allows a rendezvous point to potentially man-in-the-middle and impersonate the onion service a client is attempting to reach. The vulnerability has a high severity with a CVSS score of 8.9. Join the discussion | CVE Database V5 | 08/20/2026, 20:52:29 UTC Added: 08/20/2026, 21:07:38 UTC |
Tor versions before 0.4.9.11 contain a use-after-free vulnerability related to improper update of reference counts in conflux objects. This flaw occurs when a recovery leg revives a conflux set whose last linked leg has already been closed, potentially leading to a crash of the client. The vulnerability has a medium severity rating with a CVSS score of 5.9. Join the discussion | CVE Database V5 | 08/20/2026, 20:47:39 UTC Added: 08/20/2026, 20:52:50 UTC |
0 CVE-2026-44603 is an off-by-one error vulnerability in Tor versions before 0.4.9.7. It involves an out-of-bounds read by one byte triggered by a malformed BEGIN cell. The vulnerability is classified as CWE-193 and has a low severity with a CVSS score of 3.7. There are no known exploits in the wild, and no official patch or remediation level has been confirmed yet. Join the discussion | CVE Database V5 | 05/07/2026, 03:21:24 UTC Added: 05/07/2026, 04:22:44 UTC |
Tor before 0.4.9.7 mishandles accounting of the conflux out-of-order queue during the clearing of a queue, aka TROVE-2026-010. Join the discussion | CVE Database V5 | 05/07/2026, 02:20:51 UTC Added: 05/07/2026, 03:06:23 UTC |
Showing 1 to 10 of 12 results