Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
CVE-2026-69152: CWE-400: Uncontrolled Resource Consumption in juliangruber brace-expansionCVE-2026-69152 0 The brace-expansion library prior to versions 1.1.18, 2.1.4, 3.0.6, and 5.0.9 contains an uncontrolled resource consumption vulnerability. The expand() function does not enforce the maxLength limit when constructing certain intermediate arrays, allowing attacker-controlled input to exhaust memory or block the event loop. This vulnerability bypasses a previous fix for CVE-2026-14257 and is classified under CWE-400 and CWE-770. It has a CVSS 3.1 score of 7.5, indicating high severity. Join the discussion | CVE Database V5 | 08/03/2026, 16:33:36 UTC Added: 08/03/2026, 17:18:39 UTC |
CVE-2026-68869CVE-2026-68869 0 CVE-2026-68869 is a reserved and rejected CVE identifier with no available description, technical details, or confirmed vulnerability information. Join the discussion | CVE Database V5 | 08/03/2026, 17:18:39 UTC |
CVE-2026-18718: Uncontrolled Search Path Element in National Security Agency GhidraCVE-2026-18718 0 Ghidra contains a vulnerability in its Swift demangler analyzer that allows arbitrary code execution. An attacker can craft a malicious Ghidra project with a manipulated Swift tool directory path. When the victim opens this project, Ghidra executes attacker-controlled binaries without verifying their integrity or signature, running them with the user's privileges and without any prompt or confirmation. This vulnerability has a high severity score of 7.1. Join the discussion | CVE Database V5 | 08/03/2026, 16:54:17 UTC Added: 08/03/2026, 17:18:39 UTC |
CVE-2026-18610: Improper Authentication in NewType WebEIPCVE-2026-18610 0 CVE-2026-18610 is an improper authentication vulnerability in NewType WebEIP version 3.0 affecting the /EIP_Com_FileList.aspx file. The flaw allows remote attackers to bypass authentication controls. The vulnerability has a medium severity score of 6.9. The vendor has not responded to the disclosure, and no patch or official remediation is currently available. Exploit code is publicly available, but no known exploitation in the wild has been reported. Join the discussion | CVE Database V5 | 08/03/2026, 17:00:09 UTC Added: 08/03/2026, 17:18:39 UTC |
CVE-2026-18607: Stack-based Buffer Overflow in Wavlink WN572CVE-2026-18607 0 A stack-based buffer overflow vulnerability exists in the Wavlink WN572 and several related models due to unsafe use of strcpy in the upload.cgi component of lighttpd. The vulnerability is triggered by manipulating the HTTP_COOKIE argument remotely. This issue has a high severity score of 8.7 and has been publicly disclosed, though no known exploits in the wild have been reported. No patch or official remediation guidance is currently available. Join the discussion | CVE Database V5 | 08/03/2026, 16:45:09 UTC Added: 08/03/2026, 17:18:39 UTC |
Built a self-hosted CVE + IOC intelligence tool "BRIEFR", first module of a bigger self-hosted SIEM idea I scoped back down to size 0 BRIEFR is a self-hosted, open-source tool designed to provide CVE and IOC intelligence as part of a modular SIEM approach. It aggregates data from multiple threat intelligence sources such as NVD, CISA KEV, FIRST EPSS, and various exploit feeds, scoring CVEs against a user's technology stack. The tool also supports IOC lookups via free-tier VirusTotal, AbuseIPDB, MalwareBazzar, and URLHaus, and integrates Sigma community rules and SIEM query starters tied to ATT&CK. BRIEFR is currently in early alpha, intended for personal use with no major issues reported, and is not a vulnerability or threat itself. It is a security tool aimed at improving threat intelligence and situational awareness. Join the discussion | Reddit Cybersecurity | 08/03/2026, 10:20:47 UTC Added: 08/03/2026, 17:02:49 UTC |
CVE-2026-68930: CWE-666: Operation on Resource in Wrong Phase of Lifetime in Eugeny russhCVE-2026-68930 0 Russh is a Rust SSH client & server library. Prior to 0.62.5, russh dispatches channel-scoped Handler callbacks for recipient channel IDs that were never opened or confirmed in russh/src/server/encrypted.rs, server_read_authenticated, and the exec_request callback. Version 0.62.5 fixes the issue. Join the discussion | CVE Database V5 | 08/03/2026, 15:34:41 UTC Added: 08/03/2026, 16:18:42 UTC |
CVE-2026-61372: CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in Apache Software Foundation Apache Jena FusekiCVE-2026-61372 0 Apache Jena Fuseki versions prior to 6.2.0 contain a path traversal vulnerability (CWE-22) that allows improper limitation of a pathname to a restricted directory. This vulnerability could enable unauthorized access to files outside the intended directory. The issue is fixed in version 6.2.0. Join the discussion | CVE Database V5 | 08/03/2026, 15:41:27 UTC Added: 08/03/2026, 16:18:42 UTC |
CVE-2026-41453: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in krayin laravel-crmCVE-2026-41453 0 Krayin laravel-crm versions prior to 2.2.4 contain a blind SQL injection vulnerability in the leads DataGrid component. Authenticated users with leads access can exploit this by manipulating the rotten_lead[in] query parameter, which is improperly handled in a havingRaw() SQL call. This allows attackers to perform time-based and boolean-based blind SQL injection to extract sensitive database contents including user credentials and CRM data. Join the discussion | CVE Database V5 | 08/03/2026, 15:47:11 UTC Added: 08/03/2026, 16:18:42 UTC |
CVE-2026-41452: Missing Authentication for Critical Function in krayin laravel-crmCVE-2026-41452 0 Krayin CRM 2.2.4 contains a missing authentication vulnerability in the installer middleware that allows unauthenticated remote attackers to overwrite the primary administrator account by sending a crafted HTTP POST request with the X-Requested-With: XMLHttpRequest header to bypass the CanInstall middleware redirect check. Attackers can supply arbitrary name, email, and password values to the admin-config-setup endpoint, which performs an unauthenticated updateOrInsert targeting the hardcoded administrator user ID, enabling full administrative access to all CRM data. Join the discussion | CVE Database V5 | 08/03/2026, 15:43:05 UTC Added: 08/03/2026, 16:18:42 UTC |
Showing 1 to 10 of 21980 results