Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
CVE-2026-101001: OS Command Injection in Netcore NBR200V2CVE-2026-101001 0 A vulnerability was identified in Netcore NBR200V2 1.3.241127.071246. This impacts the function eval of the file /www/cgi-bin/network_tools of the component Web Management Interface. Such manipulation of the argument QUERY_STRING leads to os command injection. It is possible to launch the attack remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way. Join the discussion | CVE Database V5 | 09/28/2026, 05:00:13 UTC Added: 09/28/2026, 05:18:16 UTC |
0 CVE-2026-101000 is a critical vulnerability in Netcore NBR100V2 version 1.3.240614.030928. It involves a missing authorization check in the ACL Handler component, specifically in the uci.apply function within /usr/share/rpcd/acl.d/unauthenticated.json. This flaw allows remote attackers to manipulate arguments and bypass authorization controls. The vulnerability has a maximum CVSS score of 10, indicating severe impact. The vendor has not responded to disclosure requests, and no patch or mitigation guidance is currently available. Join the discussion | CVE Database V5 | 09/28/2026, 04:45:11 UTC Added: 09/28/2026, 05:03:15 UTC |
0 OctoberCMS versions up to 4.1.19, 4.2.25, and 4.3.4 contain a server-side request forgery (SSRF) vulnerability in the getSourcePathForResize function of the ResizeImages.php module. This vulnerability allows remote attackers to manipulate the realSourcePath argument, potentially causing the server to make unintended requests. The issue is resolved by upgrading to versions 4.3.5 or 4.4.0. Join the discussion | CVE Database V5 | 09/28/2026, 04:30:10 UTC Added: 09/28/2026, 04:48:29 UTC |
Multiple vulnerabilities have been identified in Wi-Fi products provided by BUFFALO INC. Specific details about these vulnerabilities, including their nature, impact, and affected versions, have not been disclosed in the available information. MediumVulnerability Join the discussion | JVN Japan | 09/28/2026, 04:30:00 UTC Added: 09/28/2026, 04:40:36 UTC |
0 CVE-2026-100908 is a stack-based buffer overflow vulnerability in the Eyeplus software version 57.0.0.0308. The flaw exists in an unknown function of the p2pcam HTTP Parser component and can be exploited remotely without authentication or user interaction. Public exploit code has been disclosed. The vulnerability has a high severity rating with a CVSS score of 8.7. Join the discussion | CVE Database V5 | 09/28/2026, 04:15:11 UTC Added: 09/28/2026, 04:34:03 UTC |
CVE-2026-87723 is an untrusted search path vulnerability in Google fuse-archive versions prior to 1.24. An attacker able to manipulate the PATH environment variable or place a malicious binary in a writable directory within PATH can hijack execution to run arbitrary code with the privileges of the fuse-archive process user. The vulnerability was partially mitigated in version 1.22 and fully fixed in version 1.24 by implementing refined selective PATH filtering. Join the discussion | CVE Database V5 | 09/28/2026, 04:02:14 UTC Added: 09/28/2026, 04:34:03 UTC |
0 CVE-2026-100907 is an information disclosure vulnerability in Eyeplus version 57.0.0.0308. The flaw exists in an unknown function within the /snapshot file of the p2pcam Service component. The vulnerability can be exploited remotely without authentication or user interaction. An exploit has been published but there are no reports of active exploitation in the wild. The CVSS 4.0 base score is 6.9, indicating a medium severity issue. Join the discussion | CVE Database V5 | 09/28/2026, 04:00:10 UTC Added: 09/28/2026, 04:34:03 UTC |
0 A vulnerability was detected in Eyeplus 57.0.0.0308. The affected element is the function GetUsers of the file /onvif/Device of the component ONVIF. The manipulation results in information disclosure. The attack can be executed remotely. The exploit is now public and may be used. Join the discussion | CVE Database V5 | 09/28/2026, 03:45:09 UTC Added: 09/28/2026, 04:03:16 UTC |
0 A security vulnerability has been detected in amirsanni mini-inventory-and-sales-management-system up to 81bf0b55f5933f3b0dbb1583204a612e06605b95. Impacted is an unknown function of the file application/controllers/Items.php of the component Items Management Module. The manipulation of the argument itemName leads to cross site scripting. Remote exploitation of the attack is possible. This product follows a rolling release approach for continuous delivery, so version details for affected or updated releases are not provided. The vendor was contacted early about this disclosure but did not respond in any way. Join the discussion | CVE Database V5 | 09/28/2026, 03:30:10 UTC Added: 09/28/2026, 03:48:19 UTC |
0 A vulnerability was identified in ООО НПО Ритм GEOritm up to 2.45.1. This affects an unknown part of the file /restapi/objects/obj-groups of the component REST API. Such manipulation of the argument objectId leads to missing authentication. The attack can be launched remotely. The exploit is publicly available and might be used. Upgrading to version 2.46 is able to mitigate this issue. It is advisable to upgrade the affected component. The vendor confirms: "In August 2026, NPO Ritm received an official vulnerability notification from the Russian Federal Service for Technical and Export Control (FSTEC Russia). The vulnerability was registered under identifier BDU:2026-11235. Following our internal investigation, we confirmed the vulnerability and implemented the necessary security fixes. The vulnerability has been fixed on our hosted GEO.RITM server at geo.ritm.ru. The fix has also been included in GEO.RITM version 2.46, which is already being distributed to our customers." Join the discussion | CVE Database V5 | 09/28/2026, 03:15:11 UTC Added: 09/28/2026, 03:33:19 UTC |
Showing 1 to 10 of 139747 results