Skip to main content

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Package: pkg:npm/@hono/node-server

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

0

A vulnerability was identified in Netcore NBR200V2 1.3.241127.071246. This impacts the function eval of the file /www/cgi-bin/network_tools of the component Web Management Interface. Such manipulation of the argument QUERY_STRING leads to os command injection. It is possible to launch the attack remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.

Join the discussion

CVE-2026-101000 is a critical vulnerability in Netcore NBR100V2 version 1.3.240614.030928. It involves a missing authorization check in the ACL Handler component, specifically in the uci.apply function within /usr/share/rpcd/acl.d/unauthenticated.json. This flaw allows remote attackers to manipulate arguments and bypass authorization controls. The vulnerability has a maximum CVSS score of 10, indicating severe impact. The vendor has not responded to disclosure requests, and no patch or mitigation guidance is currently available.

Join the discussion

OctoberCMS versions up to 4.1.19, 4.2.25, and 4.3.4 contain a server-side request forgery (SSRF) vulnerability in the getSourcePathForResize function of the ResizeImages.php module. This vulnerability allows remote attackers to manipulate the realSourcePath argument, potentially causing the server to make unintended requests. The issue is resolved by upgrading to versions 4.3.5 or 4.4.0.

Join the discussion

Multiple vulnerabilities have been identified in Wi-Fi products provided by BUFFALO INC. Specific details about these vulnerabilities, including their nature, impact, and affected versions, have not been disclosed in the available information.

MediumVulnerability
Join the discussion
0

CVE-2026-100908 is a stack-based buffer overflow vulnerability in the Eyeplus software version 57.0.0.0308. The flaw exists in an unknown function of the p2pcam HTTP Parser component and can be exploited remotely without authentication or user interaction. Public exploit code has been disclosed. The vulnerability has a high severity rating with a CVSS score of 8.7.

Join the discussion

CVE-2026-87723 is an untrusted search path vulnerability in Google fuse-archive versions prior to 1.24. An attacker able to manipulate the PATH environment variable or place a malicious binary in a writable directory within PATH can hijack execution to run arbitrary code with the privileges of the fuse-archive process user. The vulnerability was partially mitigated in version 1.22 and fully fixed in version 1.24 by implementing refined selective PATH filtering.

Join the discussion
0

CVE-2026-100907 is an information disclosure vulnerability in Eyeplus version 57.0.0.0308. The flaw exists in an unknown function within the /snapshot file of the p2pcam Service component. The vulnerability can be exploited remotely without authentication or user interaction. An exploit has been published but there are no reports of active exploitation in the wild. The CVSS 4.0 base score is 6.9, indicating a medium severity issue.

Join the discussion
0

A vulnerability was detected in Eyeplus 57.0.0.0308. The affected element is the function GetUsers of the file /onvif/Device of the component ONVIF. The manipulation results in information disclosure. The attack can be executed remotely. The exploit is now public and may be used.

Join the discussion

A security vulnerability has been detected in amirsanni mini-inventory-and-sales-management-system up to 81bf0b55f5933f3b0dbb1583204a612e06605b95. Impacted is an unknown function of the file application/controllers/Items.php of the component Items Management Module. The manipulation of the argument itemName leads to cross site scripting. Remote exploitation of the attack is possible. This product follows a rolling release approach for continuous delivery, so version details for affected or updated releases are not provided. The vendor was contacted early about this disclosure but did not respond in any way.

Join the discussion
0

A vulnerability was identified in ООО НПО Ритм GEOritm up to 2.45.1. This affects an unknown part of the file /restapi/objects/obj-groups of the component REST API. Such manipulation of the argument objectId leads to missing authentication. The attack can be launched remotely. The exploit is publicly available and might be used. Upgrading to version 2.46 is able to mitigate this issue. It is advisable to upgrade the affected component. The vendor confirms: "In August 2026, NPO Ritm received an official vulnerability notification from the Russian Federal Service for Technical and Export Control (FSTEC Russia). The vulnerability was registered under identifier BDU:2026-11235. Following our internal investigation, we confirmed the vulnerability and implemented the necessary security fixes. The vulnerability has been fixed on our hosted GEO.RITM server at geo.ritm.ru. The fix has also been included in GEO.RITM version 2.46, which is already being distributed to our customers."

Join the discussion

Showing 1 to 10 of 139747 results

Filters:Package: pkg:npm/@hono/node-server
Page 1 of 13975
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses