Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
0 CVE-2026-52875 is a path traversal vulnerability in the Streambert Electron desktop app prior to version 2.6.0. The issue arises from the perform-scheduled-backup IPC handler accepting a renderer-supplied path without verifying it is within an authorized backup directory. This allows a compromised renderer process to create or delete files outside the intended backup location. The vulnerability is fixed in version 2.6.0. Join the discussion | CVE Database V5 | 08/18/2026, 21:30:48 UTC Added: 08/18/2026, 21:50:02 UTC |
Streambert, a cross-platform Electron desktop app for streaming and downloading video content, has an improper input validation vulnerability in versions prior to 2.6.0. The open-path-at-time IPC handler accepts a file path from the renderer process without validating its type or location. If attempts to launch mpv or VLC are skipped or fail, the handler passes this file path to Electron's shell.openPath, which can cause the operating system to execute arbitrary files with the privileges of the Streambert process. This allows a compromised renderer to escape the sandbox and execute local executables or scripts. The issue is fixed in version 2.6.0. Join the discussion | CVE Database V5 | 08/18/2026, 21:29:08 UTC Added: 08/18/2026, 21:50:04 UTC |
CVE-2026-52877 is an improper input validation vulnerability in the Streambert Electron desktop app before version 2.6.0. The flaw allows a compromised renderer process to pass unvalidated URLs to Electron's shell.openExternal function, potentially causing the host to open local files or launch external applications via custom URI schemes. This vulnerability is fixed in version 2.6.0. Join the discussion | CVE Database V5 | 08/18/2026, 21:27:23 UTC Added: 08/18/2026, 21:50:04 UTC |
0 CVE-2026-52872 is a path traversal vulnerability in Streambert, a cross-platform Electron desktop app for streaming and downloading video content. Versions prior to 2.5.0 have a flaw in the downloadSubtitleFile utility where a renderer process can supply a file URI and control the destination path, allowing arbitrary file copying. This can lead to exposure of sensitive local files and overwriting of writable files. The vulnerability is fixed in version 2.5.0. Join the discussion | CVE Database V5 | 08/18/2026, 21:26:26 UTC Added: 08/18/2026, 21:50:01 UTC |
Streambert is a cross-platform Electron Desktop App to stream and download video content. Versions prior to 2.5.0 improperly validate executable paths supplied to the run-download IPC handler, allowing a compromised renderer process to execute arbitrary local binaries with the application’s privileges. Version 2.5.0 contains a patch. Join the discussion | CVE Database V5 | 08/11/2026, 13:52:45 UTC Added: 08/11/2026, 14:12:16 UTC |
0 Streambert is a cross-platform Electron Desktop App to stream and download video content. Versions prior to 2.5.0 contain an unvalidated auto-updater URL vulnerability that allows a compromised renderer process to make the main process download and execute an arbitrary binary, resulting in remote code execution. Version 2.5.0 contains a patch. Join the discussion | CVE Database V5 | 08/11/2026, 13:08:45 UTC Added: 08/11/2026, 13:41:47 UTC |
Streambert is a cross-platform Electron Desktop App to stream and download any video media. In versions 2.4.0 and prior, a high-severity Zip Slip vulnerability was identified in Streambert's subtitle extraction logic. The application does not sanitize archive entry filenames during extraction, allowing a malicious archive to perform path traversal and write arbitrary files to the host filesystem. The subtitle extraction process downloads a ZIP archive and extracts its entries. The destination file path is constructed by concatenating the raw archive entry name (extracted.name) directly to the temporary directory path. If a malicious ZIP archive containing directory traversal sequences is processed, it escapes the temporary directory boundaries. The application then writes the extracted payload anywhere on the host filesystem subject to the application's current write permissions. This issue has been fixed in version 2.5.0. Join the discussion | CVE Database V5 | 06/16/2026, 21:17:59 UTC Added: 06/16/2026, 22:01:09 UTC |
Showing 1 to 7 of 7 results