Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
0 CVE-2026-50089 is a medium severity vulnerability in the Aqara IAM/SSO Gateway that allows an open redirect to untrusted sites. This issue is classified as CWE-601 and can be exploited to facilitate phishing attacks by redirecting users to malicious URLs. The vulnerability requires no privileges and user interaction is needed to trigger the redirect. It impacts confidentiality and integrity but not availability. Join the discussion | CVE Database V5 | 06/12/2026, 15:02:02 UTC Added: 06/12/2026, 15:39:37 UTC |
0 CVE-2026-50085 is a high-severity vulnerability in the Aqara Board service that allows unauthenticated MQTT command payloads to be forwarded to the platform's HiveMQ broker. This missing authentication for a critical function (CWE-306) can lead to partial compromise of confidentiality, high impact on integrity, and low impact on availability. When combined with related vulnerabilities CVE-2026-50082, CVE-50083, and CVE-50084, it may enable a fully unauthenticated remote takeover of affected devices. Join the discussion | CVE Database V5 | 06/12/2026, 15:01:13 UTC Added: 06/12/2026, 15:39:37 UTC |
0 The Aqara IAM/SSO Gateway has a critical vulnerability due to the use of a hardcoded OAuth client credential (CWE-798). This flaw allows attackers to potentially compromise confidentiality and integrity without authentication or user interaction. The vulnerability has a CVSS score of 9.1 (critical). When combined with related vulnerabilities, it may enable a fully unauthenticated remote takeover of affected devices. No official patch or remediation guidance is currently available. Join the discussion | CVE Database V5 | 06/12/2026, 15:00:49 UTC Added: 06/12/2026, 15:39:34 UTC |
Showing 1 to 3 of 3 results