Skip to main content

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Package: pkg:npm/@langchain/community

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

Apple released major updates iOS 27 and macOS Golden Gate 27 that patch over 200 security vulnerabilities affecting kernel and multiple platform components. These flaws could lead to memory corruption, privilege escalation, system termination, and information leaks. The updates also fix a medium-severity Samba heap-based buffer overflow from 2022. No active exploitation has been reported. Users are advised to update promptly to benefit from these fixes.

HighVulnerability#macos#ios
Join the discussion

CVE-2026-1759 is a vulnerability in Secomea GateManager involving improper handling of insufficient permissions or privileges, which allows privilege escalation. The issue affects versions 11.5;0 and 11.4.625515072:0. It has been fixed in versions 11.6 and 11.4.626194074 and above. The vulnerability has a CVSS 3.1 score of 6.5, indicating a medium severity level.

Join the discussion

CVE-2026-80489 is a medium severity vulnerability in the GNU C Library (glibc) versions 2.3 through 2.44. It involves an infinite loop condition when converting crafted EUC_JISX0213 input to UCS-4 or the internal wide character encoding, such as via iconv. The flaw occurs because the converter improperly handles sequences that decode to two code points when the output buffer is too small, causing the application to hang. This affects only the EUC_JISX0213 character set, which is uncommon. No confidentiality or integrity impact is reported, but availability is affected due to the hang. No known exploits are reported, and no patch information is provided.

Join the discussion

CVE-2026-1758 is a session fixation vulnerability in the Secomea GateManager webserver module. It affects versions 11.4.625515072 and 11.5. This vulnerability allows an attacker to fixate a session ID, potentially leading to unauthorized access. The issue has been fixed in GateManager versions 11.6 and 11.4.626194074 and later.

Join the discussion

Converting crafted SHIFT_JISX0213 input to UCS-4 or the internal wide character encoding, for example with iconv, in the GNU C Library version 2.3 to 2.44 may result in the converter making no progress, causing the calling application to hang. Some SHIFT_JISX0213 sequences decode to two code points. If the output buffer has room for only the first one, the converter stores the second in the conversion state and returns E2BIG, but it never clears that pending character after emitting it on the next call. The converter then keeps emitting the pending character without consuming further input, so an application that retries the conversion loops forever. The input must be attacker controlled and the application must convert it with an output buffer small enough to split the two code points. Only the SHIFT_JISX0213 character set is affected, which is not commonly used. The related defect in the EUC_JISX0213 converter is tracked separately as CVE-2026-80489.

Join the discussion

PraisonAI versions prior to 0.1.6 contain a critical vulnerability where a hard-coded default JWT secret is used if environment variables are not set. This allows a remote unauthenticated attacker to forge valid JWT tokens and impersonate any user, gaining unauthorized access to protected API routes. The issue is fixed in version 0.1.6.

Join the discussion

PraisonAI versions prior to 0.1.6 contain an improper authentication vulnerability where the system falls back to a default public signing key if the environment variable PLATFORM_JWT_SECRET is unset. This allows an unauthenticated attacker to forge JWT tokens with arbitrary user identities, enabling impersonation of users or workspace owners. The issue is fixed in version 0.1.6.

Join the discussion

CVE-2026-57140 is a critical vulnerability in MervinPraison's PraisonAI multi-agent teams system versions 1.6.0 through 1.7.1. The flaw involves missing authentication on critical API endpoints, allowing remote unauthenticated access to agent information and the ability to invoke agents. This could expose sensitive data such as agent roles, instruction prefixes, tools, memory, external APIs, credentials, and workflow state. The issue was addressed with an initial remediation in version 1.7.2.

Join the discussion

PraisonAI versions from 1.5.0 up to but not including 1.7.2 contain a critical vulnerability where the MCPServer.startHttp() function binds without host restrictions and forwards HTTP POST requests without any authentication or authorization. This allows any network client with access to the server port to invoke sensitive functions such as tools/list, tools/call, resources/read, or prompts/get, potentially executing handlers with server-side privileges or exposing sensitive data. An initial remediation was introduced in version 1.7.2.

Join the discussion

CVE-2026-57133 is an OS command injection vulnerability in MervinPraison's PraisonAI multi-agent teams system. Versions from 1.5.1 up to but not including 1.7.2 are affected. The vulnerability arises because the shell() helper only validates the first whitespace-delimited token against a safe command list but then executes the entire input string, allowing an attacker to append additional commands. This can lead to arbitrary command execution with the privileges of the PraisonAI process. The issue is fixed in version 1.7.2.

Join the discussion

Showing 1 to 10 of 131765 results

Filters:Package: pkg:npm/@langchain/community
Page 1 of 13177
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses