Skip to main content

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Package: pkg:npm/@adonisjs/bodyparser

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

Cisco has released a patch for a critical zero-day vulnerability in its Secure Email Gateway product that has been actively exploited by threat actors. Customers are urged to apply the patch promptly to mitigate the risk. No detailed technical information or CVSS score is available at this time.

Join the discussion
0

A vulnerability was determined in GPAC up to f1219cde. The affected element is the function gf_node_activate_ex of the file scenegraph/base_scenegraph.c. This manipulation causes stack-based buffer overflow. It is possible to launch the attack on the local host. The exploit has been publicly disclosed and may be utilized. Upgrading to version abi-16.23 is sufficient to fix this issue. Patch name: 9eb40df4448b88d6a6ce3454657c06f47eff0b24. The affected component should be upgraded.

Join the discussion
0

CVE-2026-91089 is a use-after-free vulnerability in the GPAC multimedia framework affecting the function gf_node_get_name_and_id in scenegraph/base_scenegraph.c. This vulnerability allows remote attackers to exploit the flaw, potentially leading to memory corruption. An exploit has been publicly disclosed. The issue is addressed by upgrading to GPAC version abi-16.23, which contains the patch identified by commit 49dee5cad329cfed310c1682703df7daa47df31a.

Join the discussion

CVE-2026-91778 is a high-severity vulnerability in Octopus Deploy's Octopus Server where users with certain scoped permissions can execute arbitrary scripts on a worker without proper authorization. This occurs due to incorrect permission validation during script execution, allowing actions beyond the user's intended privileges.

Join the discussion

The Job Postings plugin for WordPress, developed by blueglassch, contains a stored cross-site scripting (XSS) vulnerability in the 'position_button' parameter. This affects all versions up to and including 2.8.1. Authenticated users with contributor-level access or higher can inject malicious scripts that execute when other users view the affected pages. The vulnerability arises from insufficient input sanitization and output escaping.

Join the discussion
0

CVE-2026-91088 is a heap-based buffer overflow vulnerability in the GPAC project's URL Handler component, specifically in the gf_url_concatenate_ex function of utils/url.c. This vulnerability affects GPAC versions up to commit f1219cde. Exploitation requires local access with low privileges and user interaction. The issue is addressed by upgrading to GPAC version abi-16.23.

Join the discussion
0

CVE-2026-91087 is a use-after-free vulnerability in the GPAC multimedia framework affecting the gf_mo_get_od_id function in compositor/media_object.c. This flaw can be triggered remotely and may lead to memory corruption. An exploit is publicly available. The issue is resolved by upgrading to GPAC version abi-16.24.

Join the discussion
0

CVE-2026-91086 is a heap-based buffer overflow vulnerability in the GPAC MPEG Video Reframer component, specifically in the mpgviddmx_process function. This vulnerability affects GPAC versions up to commit f1219cde. The flaw can be exploited remotely and has been publicly disclosed. A patch is available in version abi-16.23, which addresses this issue. Users are advised to upgrade to this version to mitigate the risk.

Join the discussion

CVE-2026-91005 is a medium severity vulnerability in SourceCodester Online Faculty Clearance System version 1.0. It involves an unrestricted file upload flaw in the move_uploaded_file function within production/edit_picture.php, allowing remote attackers to upload arbitrary files. An exploit for this vulnerability has been publicly disclosed.

Join the discussion

The Eventin WordPress plugin up to version 4.1.23 contains a privilege escalation vulnerability. The flaw arises because the plugin's permission management function grants all capabilities to the user with ID 1 unconditionally, regardless of their assigned role. This allows an attacker with user ID 1 but a lower-privilege role to gain administrator-level permissions, potentially leading to full site takeover and remote code execution via plugin or theme editors. The vulnerability is only exploitable if the user ID 1 account has been demoted from administrator, which is a common security hardening practice. Default installations where user ID 1 remains an administrator are not affected by privilege escalation.

Join the discussion

Showing 1 to 10 of 131722 results

Filters:Package: pkg:npm/@adonisjs/bodyparser
Page 1 of 13173
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses