Skip to main content

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Package: pkg:npm/@acastellon/auth

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

A security flaw has been discovered in SourceCodester Car Driving School Management System 1.0. Impacted is an unknown function of the file /classes/Master.php?f=save_enrollment. The manipulation results in sql injection. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks.

Join the discussion

PCRE2 before 10.49, when there is an attacker-controlled regular expression and certain JIT API usage, allows an out-of-bounds write with arbitrary data.

Join the discussion

CVE-2026-102912 is a SQL injection vulnerability in SourceCodester Online Leave Management System version 1.0. It affects the processing of the /admin/?page=reports file, specifically the date_start and date_end parameters. This vulnerability allows remote attackers with high privileges to manipulate SQL queries. The exploit code is publicly available, but no active exploitation in the wild has been reported. The vulnerability has a medium severity rating with a CVSS 4.0 score of 5.1.

Join the discussion

CVE-2026-102911 is a critical OS command injection vulnerability in the zosmaai pi-llm-wiki product affecting versions 0.11.0 through 0.11.7. The flaw exists in an unknown function within the mcp/index.ts file of the wiki_capture_source MCP tool component. Remote attackers can exploit this by manipulating the 'url' argument to execute arbitrary OS commands. An exploit has been published. Upgrading to version 0.11.8 addresses the issue.

Join the discussion
0

CVE-2026-86134 is a high-severity NULL pointer dereference vulnerability in WatchGuard Fireware OS affecting multiple versions. It allows a remote, unauthenticated attacker to crash the management daemon by sending a specially crafted request to the login interface, causing a denial of service. The vulnerability impacts several version ranges of Fireware OS prior to specific patch levels.

Join the discussion

CVE-2026-102910 is a SQL injection vulnerability in SourceCodester Online Reviewer Management System version 1.0. It affects the exam-delete.php script via the test_id parameter, allowing remote attackers to manipulate SQL queries. The vulnerability has a medium severity with a CVSS score of 6.9. Exploit code has been publicly released, increasing the risk of attacks. No official patch or remediation information is currently available.

Join the discussion

A path traversal vulnerability has been identified in FUJIFILM Business Innovation and Sharp multifunction printers (MFPs). This vulnerability could allow unauthorized access to files outside the intended directories on affected devices. No specific affected versions or detailed technical information are provided.

MediumVulnerability
Join the discussion

CVE-2026-103110 is a critical out-of-bounds write vulnerability in Pexip Infinity conferencing software. It affects versions prior to 38.2, as well as versions 39.0, 39.1, and 40.0. The flaw allows a remote attacker to execute arbitrary code on a Pexip Infinity Conferencing Node with unprivileged user rights without requiring user interaction.

Join the discussion

A vulnerability was identified in SourceCodester Online Reviewer Management System 1.0. Impacted is an unknown function of the file /reviewer_0/admins/assessments/examproper/btn_functions.php. The manipulation of the argument access_code leads to sql injection. The attack can be initiated remotely. The exploit is publicly available and might be used.

Join the discussion

Pexip Infinity before 38.2, plus 39.0, 39.1 and 40.0, is affected by improper input validation in the media implementation that allows a remote attacker to trigger memory corruption or a software abort resulting in a denial of service. A crafted media stream may result in a controlled abort during processing, and has the potential to achieve memory corruption.

Join the discussion

Showing 1 to 10 of 140866 results

Filters:Package: pkg:npm/@acastellon/auth
Page 1 of 14087
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses