Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
A vulnerability in warmcat libwebsockets 4.5.0 affects the function report_raw_cbor in the LECP CBOR Recording component, causing an out-of-bounds write. This flaw can be exploited remotely without authentication. A patch has been identified to fix the issue. The vulnerability has a CVSS score of 7.3, indicating a medium severity level. Join the discussion | GCVE Database | 08/24/2026, 03:31:05 UTC Added: 08/24/2026, 13:51:56 UTC |
0 CVE-2026-78161 is an out-of-bounds write vulnerability in warmcat libwebsockets version 4.5.0. The flaw exists in the report_raw_cbor function within the LECP CBOR Recording component. This vulnerability can be exploited remotely without authentication. A patch has been identified to address this issue. The CVSS 4.0 base score is 6.9, indicating a medium severity level. Join the discussion | CVE Database V5 | 08/24/2026, 00:45:08 UTC Added: 08/24/2026, 01:07:38 UTC |
A flaw has been found in warmcat libwebsockets up to 4.5.8. This issue affects the function lws_ssh_parse_plaintext of the file plugins/protocol_lws_ssh_base/sshd.c of the component SSH Protocol Handler. Executing a manipulation of the argument msg_len can lead to resource consumption. The attack may be launched remotely. The exploit has been published and may be used. This patch is called 3f9f0c6ecaf0e6f3f219d30632c5d1f2479d7498. A patch should be applied to remediate this issue. Join the discussion | CVE Database V5 | 06/02/2026, 21:15:10 UTC Added: 06/02/2026, 21:48:37 UTC |
Out-of-bounds Write in unfilter_scanline in warmcat libwebsockets allows, when the LWS_WITH_UPNG flag is enabled during compilation and the HTML display stack is used, to write past a heap allocated buffer possibly causing a crash, when the user visits an attacker controlled website that contains a crafted PNG file with a big width value that causes an integer overflow which value is used for determining the size of a heap allocation. Join the discussion | CVE Database V5 | 10/20/2025, 14:04:06 UTC Added: 10/20/2025, 14:13:40 UTC |
Out-of-bounds Read in lws_upng_emit_next_line in warmcat libwebsockets allows, when the LWS_WITH_UPNG flag is enabled during compilation and the HTML display stack is used, to read past a heap allocated buffer possibly causing a crash, when the user visits an attacker controlled website that contains a crafted PNG file with a big height dimension. Join the discussion | CVE Database V5 | 10/20/2025, 13:58:31 UTC Added: 10/20/2025, 14:13:40 UTC |
Stack-based Buffer Overflow in lws_adns_parse_label in warmcat libwebsockets allows, when the LWS_WITH_SYS_ASYNC_DNS flag is enabled during compilation, to overflow the label_stack, when the attacker is able to sniff a DNS request in order to craft a response with a matching id containing a label longer than the maximum. Join the discussion | CVE Database V5 | 10/20/2025, 13:51:17 UTC Added: 10/20/2025, 13:59:02 UTC |
Use After Free in WebSocket server implementation in lws_handshake_server in warmcat libwebsockets may allow an attacker, in specific configurations where the user provides a callback function that handles LWS_CALLBACK_HTTP_CONFIRM_UPGRADE, to achieve denial of service. Join the discussion | CVE Database V5 | 10/20/2025, 13:41:10 UTC Added: 10/20/2025, 13:50:36 UTC |
Showing 1 to 7 of 7 results