Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
CVE-2026-91782: NULL Pointer Dereference in GNU BinutilsCVE-2026-91782 0 A vulnerability was detected in GNU Binutils 2.47. Affected by this vulnerability is the function elf_x86_allocate_dynrelocs of the file bfd/elfxx-x86.c of the component Dynamic Relocation Allocation. The manipulation results in null pointer dereference. The attack requires a local approach. The exploit is now public and may be used. Upgrading to version 2.48 addresses this issue. The patch is identified as d1268210b6f6/471130b39c0/283d3198bed/0a84e560216/a692a633d40. Upgrading the affected component is recommended. Join the discussion | CVE Database V5 | 09/15/2026, 09:00:14 UTC Added: 09/15/2026, 09:02:05 UTC |
Hidden functionality issue exists in FF-RFI079I4 and FF-RFI078I4, which may allow a user who can log in via SSH and access the enable mode on the product to execute arbitrary OS commands. Join the discussion | CVE Database V5 | 09/15/2026, 08:50:13 UTC Added: 09/15/2026, 09:02:05 UTC |
Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in FF-RFI079I4 and FF-RFI078I4. A user who can log in to the product's M-Plane (NETCONF) may execute arbitrary OS commands. Join the discussion | CVE Database V5 | 09/15/2026, 08:49:58 UTC Added: 09/15/2026, 09:02:05 UTC |
Stack-based buffer overflow vulnerability in Samsung Opensource rLottie allows attackers to overflow buffers, leading to memory corruption when rendering crafted vector animations. This issue affects rLottie: 480a2ad0c5d2e45458c545b8213279e9e8b71e39. Join the discussion | CVE Database V5 | 09/15/2026, 08:49:48 UTC Added: 09/15/2026, 09:02:05 UTC |
CVE-2026-91781: NULL Pointer Dereference in GNU BinutilsCVE-2026-91781 0 A security vulnerability has been detected in GNU Binutils 2.47. Affected is the function elf_x86_64_common_section_index of the file bfd/elf64-x86-64.c of the component ELF Section Handler. The manipulation leads to null pointer dereference. The attack needs to be performed locally. The exploit has been disclosed publicly and may be used. Upgrading to version 2.48 is able to address this issue. The identifier of the patch is 7322e9bc30cb282575a701c307851fd3d66fee68. It is suggested to upgrade the affected component. Join the discussion | CVE Database V5 | 09/15/2026, 08:45:14 UTC Added: 09/15/2026, 09:02:05 UTC |
Microsoft has acknowledged that the September 2026 security update KB5002914 for Excel causes copy and paste operations to silently fail for some users. This issue affects the usability of Excel but does not indicate a security vulnerability or exploitation. No affected versions or patch status details are provided. LowNews Join the discussion | Bleeping Computer | 09/15/2026, 08:40:20 UTC Added: 09/15/2026, 08:46:40 UTC |
0 CVE-2026-91780 is a medium severity vulnerability in GNU Binutils 2.47 involving a null pointer dereference in the elf_link_add_object_symbols function within bfd/elflink.c. The flaw requires local access to exploit and could lead to a denial of service or application crash. Public exploit code is available, but no vendor response or patch has been issued yet. Join the discussion | CVE Database V5 | 09/15/2026, 08:30:15 UTC Added: 09/15/2026, 08:47:13 UTC |
0 CVE-2026-75092 is a privilege escalation vulnerability in the leapp-upgrade-el9toel10 tool used during Red Hat Enterprise Linux upgrades from version 9 to 10. The flaw arises because the scan_mysql actor runs the MySQL daemon validation command as root, bypassing normal user restrictions. An attacker with OS-level access as the mysql user can place malicious plugins in a MySQL-owned directory, which are then loaded during the upgrade process with root privileges. This allows arbitrary code execution as root in an unconfined SELinux domain when an administrator runs the upgrade workflow. The vulnerability requires prior compromise of the mysql OS identity and administrator invocation of the upgrade process. No patch or mitigation currently meets Red Hat's criteria for deployment. Join the discussion | CVE Database V5 | 09/15/2026, 08:23:12 UTC Added: 09/15/2026, 08:32:04 UTC |
0 CVE-2026-91779 is a medium severity vulnerability in GNU Binutils 2.47 affecting the Eh Frame Handler component. It involves a null pointer dereference in the _bfd_elf_eh_frame_section_offset function, which can be triggered by a local attacker. The vulnerability has a CVSS score of 4.8 and public exploit code is available. The vendor has not yet responded or issued a patch. Join the discussion | CVE Database V5 | 09/15/2026, 08:15:22 UTC Added: 09/15/2026, 08:32:04 UTC |
0 CVE-2026-91091 is a medium severity memory corruption vulnerability in the GPAC software, specifically in the function gf_node_list_insert_child within the Node Insertion component. This vulnerability affects GPAC versions up to commit f1219cde. The flaw allows remote attackers to cause memory corruption, and public exploit code is available. The issue is resolved by upgrading to GPAC version abi-16.23. Join the discussion | CVE Database V5 | 09/15/2026, 07:45:10 UTC Added: 09/15/2026, 08:02:23 UTC |
Showing 1 to 10 of 131732 results