Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
A cross-site scripting (XSS) vulnerability exists in the Evernote and Google Keep note importers in Standard Notes for Android versions through 3.201.24. This flaw allows an attacker to execute arbitrary JavaScript within the application context when a victim imports a specially crafted .enex or Google Keep HTML file. Exploitation can lead to theft of encryption keys and note data, as well as arbitrary invocation of native device APIs. Join the discussion | GCVE Database | 09/07/2026, 12:30:29 UTC Added: 09/07/2026, 16:08:55 UTC |
0 A vulnerability was determined in Tuya App and SDK 24.07.11 on Android. Affected by this vulnerability is an unknown functionality of the component JSON Data Point Handler. This manipulation of the argument cruise_time causes denial of service. Remote exploitation of the attack is possible. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been publicly disclosed and may be utilized. There is ongoing doubt regarding the real existence of this vulnerability. The vendor disagrees with the conclusion of the finding: "The described vulnerability fails to prove its feasibility or exploitability by attackers. The issue essentially does not constitute a security vulnerability, aligning more closely with abnormal product functionality." These considerations are properly reflected within the CVSS vector. Join the discussion | CVE Database V5 | 03/03/2026, 15:02:08 UTC Added: 03/03/2026, 15:18:21 UTC |
Octo-STS is a GitHub App that acts like a Security Token Service (STS) for the GitHub API. Octo-STS versions before v0.5.3 are vulnerable to unauthenticated SSRF by abusing fields in OpenID Connect tokens. Malicious tokens were shown to trigger internal network requests which could reflect error logs with sensitive information. Upgrade to v0.5.3 to resolve this issue. This version includes patch sets to sanitize input and redact logging. Join the discussion | CVE Database V5 | 06/26/2025, 16:46:09 UTC Added: 06/27/2025, 13:29:14 UTC |
Showing 1 to 3 of 3 results