Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
CVE-2026-70906 is a high-severity vulnerability in Oracle Java SE 25.0.4 and 26.0.2 affecting the 2D component. It allows an unauthenticated attacker with network access via multiple protocols to cause a denial of service by hanging or crashing the Java SE environment. The vulnerability can be exploited through APIs, including via sandboxed Java Web Start applications or applets running untrusted code. The CVSS 3.1 base score is 7.5, reflecting significant availability impact without confidentiality or integrity loss. Join the discussion | CVE Database V5 | 08/29/2026, 00:00:00 UTC Added: 08/18/2026, 21:20:45 UTC |
CVE-2026-70907 is a vulnerability in the JSSE component of Oracle Java SE, Oracle GraalVM for JDK, and Oracle GraalVM Enterprise Edition. It allows an unauthenticated attacker with network access via TLS to cause a partial denial of service. The vulnerability affects specific versions of Oracle Java SE, GraalVM for JDK, and GraalVM Enterprise Edition. The CVSS 3.1 base score is 5.3, indicating a medium severity impact focused on availability. Exploitation requires supplying data to APIs in the JSSE component without using untrusted Java Web Start applications or applets. Oracle has released security patches addressing this and recommends applying them promptly. Join the discussion | CVE Database V5 | 08/18/2026, 21:02:27 UTC Added: 08/18/2026, 21:20:45 UTC |
CVE-2026-61308 is a vulnerability in Oracle Java SE, Oracle GraalVM for JDK, and Oracle GraalVM Enterprise Edition affecting the Networking component. It allows an unauthenticated attacker with network access via HTTP to potentially gain unauthorized access to critical data. The vulnerability is difficult to exploit and impacts multiple supported versions. Successful exploitation can lead to unauthorized access to all accessible data within the affected products. The vulnerability also affects Java deployments running sandboxed Java Web Start applications or applets that load untrusted code. The CVSS 3.1 base score is 6.8, indicating a medium severity with high confidentiality impact but no integrity or availability impact. Oracle has released a Critical Security Patch Update addressing this and many other vulnerabilities and strongly recommends applying patches promptly. Join the discussion | CVE Database V5 | 08/18/2026, 21:00:04 UTC Added: 08/18/2026, 21:08:30 UTC |
CVE-2026-60589 is a low-severity vulnerability in Oracle Java SE, Oracle GraalVM for JDK, and Oracle GraalVM Enterprise Edition. It allows an unauthenticated attacker with network access via multiple protocols to gain unauthorized read access to certain accessible data. Exploitation requires supplying data to specific APIs without using untrusted Java Web Start applications or applets. The vulnerability affects specific versions of Oracle Java SE, GraalVM for JDK, and GraalVM Enterprise Edition. Join the discussion | CVE Database V5 | 08/18/2026, 20:58:55 UTC Added: 08/18/2026, 21:07:55 UTC |
CVE-2026-60166 is a vulnerability in Oracle Java SE 8u491 affecting the JavaFX component. It allows an unauthenticated attacker with network access via multiple protocols to potentially gain unauthorized read access to some data accessible by Oracle Java SE. Exploitation is difficult and requires human interaction from a person other than the attacker. This vulnerability primarily affects client-side Java deployments running untrusted code in sandboxed environments, such as Java Web Start applications or applets. Server-side Java deployments running only trusted code are not affected. The CVSS 3.1 base score is 3.1, indicating a low severity impact focused on confidentiality. No official patch or remediation level is currently specified by Oracle. Oracle recommends applying security patches promptly but has not explicitly confirmed a fix for this specific vulnerability in the provided advisory. Join the discussion | CVE Database V5 | 07/21/2026, 21:33:28 UTC Added: 07/21/2026, 21:38:28 UTC |
CVE-2026-60164 is a low-severity vulnerability in Oracle Java SE 8u491 affecting the JavaFX component. It allows an unauthenticated attacker with network access via multiple protocols to potentially gain unauthorized read access to some data accessible by Oracle Java SE. Exploitation is difficult and requires human interaction from a person other than the attacker. This vulnerability primarily affects client-side Java deployments running sandboxed Java Web Start applications or applets that load untrusted code. Server-side deployments running only trusted code are not affected. The CVSS 3.1 base score is 3.1, reflecting limited confidentiality impact without integrity or availability effects. Oracle has not explicitly stated a patch or fix for this specific vulnerability in the provided advisory, but recommends applying Critical Patch Updates promptly. Join the discussion | CVE Database V5 | 07/21/2026, 21:33:27 UTC Added: 07/21/2026, 21:38:28 UTC |
CVE-2026-60147 is a vulnerability in Oracle Java SE, Oracle GraalVM for JDK, and Oracle GraalVM Enterprise Edition affecting multiple specified versions. It allows an unauthenticated attacker with network access via multiple protocols to gain unauthorized read and write access to some accessible data. The vulnerability involves the Security component and can be exploited through APIs, including web services and sandboxed Java applications that run untrusted code. The CVSS 3.1 base score is 6.5, indicating a medium severity level. No official patch or remediation level is confirmed in the advisory, and no known exploits in the wild have been reported. Oracle strongly recommends applying security patches promptly as part of their Critical Patch Update process. Join the discussion | CVE Database V5 | 07/21/2026, 21:33:22 UTC Added: 07/21/2026, 21:38:26 UTC |
CVE-2026-47063 is a high-severity vulnerability in Oracle Java SE, Oracle GraalVM for JDK, and Oracle GraalVM Enterprise Edition affecting multiple specified versions. It allows an unauthenticated attacker with network access via multiple protocols to compromise the affected products by unauthorized creation, deletion, or modification of critical data. The vulnerability arises from issues in the Libraries component and can be exploited through APIs, including web services and sandboxed Java applications running untrusted code. The CVSS 3.1 base score is 7.5, indicating a high impact on integrity without affecting confidentiality or availability. Oracle has published a Critical Patch Update advisory addressing multiple vulnerabilities but does not explicitly confirm patch availability for this specific CVE in the provided data. Join the discussion | CVE Database V5 | 07/21/2026, 21:33:20 UTC Added: 07/21/2026, 21:38:24 UTC |
Vulnerability in Oracle Java SE (component: Scripting). Supported versions that are affected are Oracle Java SE: 8u491, 8u491-perf and 11.0.31. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Java SE accessible data as well as unauthorized access to critical data or complete access to all Oracle Java SE accessible data. Note: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. CVSS 3.1 Base Score 7.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N). Join the discussion | CVE Database V5 | 07/21/2026, 21:33:18 UTC Added: 07/21/2026, 21:38:24 UTC |
CVE-2026-47057 is a high-severity vulnerability in Oracle Java SE's Scripting component affecting versions 8u491, 8u491-perf, and 11.0.31. It allows an unauthenticated attacker with network access via multiple protocols to cause a denial of service by hanging or crashing the Java SE environment. The vulnerability can be exploited through APIs, including those used by sandboxed Java Web Start applications or applets that run untrusted code. The CVSS 3.1 base score is 7.5, reflecting a significant availability impact without confidentiality or integrity loss. No official patch or remediation level is currently confirmed in the vendor advisory. Oracle recommends applying security patches promptly and staying on actively supported versions. The vendor advisory linked does not explicitly confirm patch availability for this specific vulnerability yet. Join the discussion | CVE Database V5 | 07/21/2026, 21:33:18 UTC Added: 07/21/2026, 21:38:23 UTC |
Showing 1 to 10 of 33 results