Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

CVE-2026-72506: Incorrectly specified destination in a communication channel in National Institute of Information and Communications Technology "VoiceTra(Voice Translator)" for AndroidCVE-2026-72506
0

VoiceTra (Voice Translator) for Android version 9.1.3 contains a vulnerability where the destination in a communication channel is incorrectly specified. This flaw could cause users to be redirected to an attacker-controlled server or service, potentially leading to theft of input data or the display of incorrect translation results. The vulnerability has a medium severity rating with a CVSS score of 5.4. No official patch or remediation guidance is currently available.

Join the discussion
CVE-2026-18728: Integer Underflow (Wrap or Wraparound) in Red Hat Red Hat Enterprise Linux 10CVE-2026-18728
0

An integer underflow vulnerability exists in the iscsiuio component of open-iscsi on Red Hat Enterprise Linux 10, specifically during IPv4 DHCP parsing. A remote attacker on the same local network segment can send a crafted IPv4/UDP DHCP reply to trigger an out-of-bounds read, causing the iscsiuio process to crash and resulting in a denial of service. This issue requires iscsiuio to be actively handling IPv4 DHCP traffic and specific network conditions to be exploitable.

Join the discussion
CVE-2026-0301: CWE-908 Use of Uninitialized Resource in Palo Alto Networks Cloud NGFWCVE-2026-0301
0

CVE-2026-0301 is a low-severity information disclosure vulnerability in the URL Filtering feature of Palo Alto Networks PAN-OS software for Cloud NGFW. It allows an unauthenticated user with network access to obtain sensitive information. Panorama products are not affected. The vulnerability is related to the use of uninitialized resources (CWE-908). No patch or official remediation guidance is currently provided.

Join the discussion
CVE-2026-0299: CWE-426 Untrusted Search Path in Palo Alto Networks GlobalProtect AppCVE-2026-0299
0

Local privilege escalation vulnerabilities in the Palo Alto Networks GlobalProtect™ app enable a local user to escalate their privileges to NT AUTHORITY\SYSTEM on Windows, and root on macOS and Linux. This enables a non-administrative user to execute arbitrary commands with administrative privileges. The GlobalProtect app on iOS, Android, and Chrome OS is not affected.

Join the discussion
CVE-2026-0298: CWE-94 Improper Control of Generation of Code ('Code Injection') in Palo Alto Networks GlobalProtect AppCVE-2026-0298
0

An improper input validation vulnerability exists in the Windows Pre-Logon Access Provider (PLAP) component of the Palo Alto Networks GlobalProtect™ app on Windows devices which enables a man-in-the-middle (MitM) attacker to execute arbitrary code with SYSTEM privileges on an affected client. The GlobalProtect app on Linux, macOS, iOS, Android, and Chrome OS is not affected.

Join the discussion
CVE-2026-0297: CWE-787 Out-of-bounds Write in Palo Alto Networks GlobalProtect AppCVE-2026-0297
0

A buffer overflow vulnerability exists in the Palo Alto Networks GlobalProtect™ app that enables a man-in-the-middle (MitM) attacker or a rogue gateway to disrupt system processes and potentially execute arbitrary code with elevated privileges (SYSTEM privileges on Windows, and root privileges on macOS and Linux).

Join the discussion
CVE-2026-0296: CWE-295 Improper Certificate Validation in Palo Alto Networks GlobalProtect AppCVE-2026-0296
0

CVE-2026-0296 is an improper certificate validation vulnerability in the Palo Alto Networks GlobalProtect app versions 6.0.0, 6.2.0, and 6.3.0. This flaw allows an unauthenticated attacker with man-in-the-middle access to intercept and modify application communications, though VPN tunnel traffic remains unaffected. The vulnerability does not impact the GlobalProtect app on iOS, Android, or Chrome OS. The CVSS score is 4.5, indicating a medium severity issue.

Join the discussion
CVE-2026-0295: CWE-362 Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') in Palo Alto Networks GlobalProtect AppCVE-2026-0295
0

A race condition in the Palo Alto Networks GlobalProtect™ client on macOS enables a locally authenticated low-privileged attacker to escalate their privileges to root. The GlobalProtect app on Linux, Windows, iOS, Android, and Chrome OS is not affected.

Join the discussion
CVE-2026-0294: CWE-427: Uncontrolled Search Path Element in Palo Alto Networks Prisma Access AgentCVE-2026-0294
0

CVE-2026-0294 is a privilege escalation vulnerability in the Palo Alto Networks Prisma Access Agent on Windows and macOS. It allows a local user to execute code with elevated privileges due to an uncontrolled search path element. Other platforms like Linux, iOS, Android, and ChromeOS are not affected. The vulnerability has a medium severity rating with a CVSS score of 6. No patch or official remediation guidance is currently available.

Join the discussion
CVE-2026-0293: CWE-693 Protection Mechanism Failure in Palo Alto Networks Prisma Access AgentCVE-2026-0293
0

CVE-2026-0293 is a medium severity vulnerability in Palo Alto Networks Prisma Access Agent on Windows. It allows a local attacker with administrator privileges to bypass the anti-tamper protection, potentially gaining unauthorized access to protected processes and files. Other operating systems running the Prisma Access Agent are not affected. No patch or official remediation has been confirmed yet.

Join the discussion

Showing 1 to 10 of 24471 results

Filters:Package: pkg:npm/@auth/core
Page 1 of 2448
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses