Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
VMware Workstation and Fusion contain a stack-based buffer-overflow vulnerability in HGFS. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process running on the host. Affected versions: - VMware Workstation: 25H2, 26H1 (fixed in 26H1u1) - VMware Fusion: 25H2, 26H1 (fixed in 26H1u1) Join the discussion | CVE Database V5 | 10/07/2026, 05:40:05 UTC Added: 10/07/2026, 06:04:12 UTC |
VMware Workstation and Fusion contain an integer-overflow vulnerability. A malicious actor with local administrative privileges on a virtual machine with VMXNET3 virtual network adapter may exploit this issue to execute code on the host. Affected versions: - VMware Workstation: 25H2, 26H1 (fixed in 26H1u1) - VMware Fusion: 25H2, 26H1 (fixed in 26H1u1) Join the discussion | CVE Database V5 | 10/07/2026, 05:40:03 UTC Added: 10/07/2026, 06:04:12 UTC |
0 CVE-2026-85217 is a high-severity vulnerability in Autodesk Fusion Desktop where a malicious add-in can alter persistent network proxy settings without user consent. This can redirect authenticated network traffic through an attacker-controlled proxy, risking exposure of sensitive user information. Join the discussion | CVE Database V5 | 09/10/2026, 13:29:58 UTC Added: 09/10/2026, 13:38:03 UTC |
A maliciously crafted HTML payload in a component name, when displayed during the delete confirmation dialog and clicked by a user, can trigger a Stored Cross-site Scripting (XSS) vulnerability in the Autodesk Fusion desktop application. A malicious actor may leverage this vulnerability to read local files or execute arbitrary code in the context of the current process. Join the discussion | CVE Database V5 | 04/14/2026, 13:56:56 UTC Added: 04/14/2026, 14:32:18 UTC |
A maliciously crafted HTML payload in an assembly variant name, when displayed during the delete confirmation dialog and clicked by a user, can trigger a Stored Cross-site Scripting (XSS) vulnerability in the Autodesk Fusion desktop application. A malicious actor may leverage this vulnerability to read local files or execute arbitrary code in the context of the current process. Join the discussion | CVE Database V5 | 04/14/2026, 13:47:01 UTC Added: 04/14/2026, 14:32:18 UTC |
A maliciously crafted HTML payload, stored in a component’s description and clicked by a user, can trigger a Stored Cross-site Scripting (XSS) vulnerability in the Autodesk Fusion desktop application. A malicious actor may leverage this vulnerability to read local files or execute arbitrary code in the context of the current process. Join the discussion | CVE Database V5 | 01/22/2026, 16:59:34 UTC Added: 01/22/2026, 17:20:59 UTC |
A maliciously crafted HTML payload, stored in a part’s attribute and clicked by a user, can trigger a Stored Cross-site Scripting (XSS) vulnerability in the Autodesk Fusion desktop application. A malicious actor may leverage this vulnerability to read local files or execute arbitrary code in the context of the current process. Join the discussion | CVE Database V5 | 01/22/2026, 16:59:01 UTC Added: 01/22/2026, 17:20:59 UTC |
A maliciously crafted HTML payload in a design name, when displayed during the delete confirmation dialog and clicked by a user, can trigger a Stored Cross-site Scripting (XSS) vulnerability in the Autodesk Fusion desktop application. A malicious actor may leverage this vulnerability to read local files or execute arbitrary code in the context of the current process. Join the discussion | CVE Database V5 | 01/22/2026, 16:58:43 UTC Added: 01/22/2026, 17:20:59 UTC |
0 CVE-2023-53689 is a reflected cross-site scripting (XSS) vulnerability in Nagios Fusion versions prior to 4.2.0, specifically in the license key configuration flow. An attacker can craft a malicious URL that, when visited by an authenticated user with administrative privileges, executes attacker-controlled scripts in the user's browser. This can lead to session or credential theft and unauthorized administrative actions, although the server itself is not directly compromised. The vulnerability requires user interaction and high privileges but no authentication bypass. It has a CVSS score of 6.0 (medium severity). European organizations using Nagios Fusion for IT infrastructure monitoring should prioritize patching or mitigating this issue to prevent browser-based attacks targeting administrators. Join the discussion | CVE Database V5 | 10/30/2025, 21:20:59 UTC Added: 10/30/2025, 21:40:50 UTC |
0 CVE-2023-53690 is a stored cross-site scripting (XSS) vulnerability affecting Nagios Fusion versions prior to 4.2.0. The flaw exists in the LDAP/AD authentication-server configuration, where unsanitized user input can be stored and later rendered in the administrative UI. This allows an attacker with privileges to add authentication servers to inject malicious JavaScript that executes in the browsers of other users viewing the affected page. Exploitation requires high privileges to add LDAP/AD servers and user interaction to trigger the payload. The vulnerability has a CVSS 4.0 score of 6.2, indicating medium severity. No known exploits are currently reported in the wild. Join the discussion | CVE Database V5 | 10/30/2025, 21:20:37 UTC Added: 10/30/2025, 21:40:50 UTC |
Showing 1 to 10 of 12 results