Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
CVE-2026-79516: n/aCVE-2026-79516 0 An out-of-bounds read in the stbsp_vsnprintf function (stb_sprintf.h) of nothings stb commit 31c1ad3 allows attackers to cause a Denial of Service (DoS) via sending a crafted input. Join the discussion | CVE Database V5 | 09/09/2026, 00:00:00 UTC Added: 09/09/2026, 20:52:42 UTC |
CVE-2026-71808: n/aCVE-2026-71808 0 A SQL Injection vulnerability in Siam Ordering (siam-server) 1.0.0 allows remote authenticated attackers to execute arbitrary SQL commands via the ${} string concatenation in AdminMapper.java and multiple other Mapper files (including MerchantWithdrawRecordMapper.java and MemberWithdrawRecordMapper.java). Join the discussion | CVE Database V5 | 09/09/2026, 00:00:00 UTC Added: 09/09/2026, 20:52:42 UTC |
CVE-2026-71803: n/aCVE-2026-71803 0 money-pos 1.0 contains a stored Cross-Site Scripting (XSS) vulnerability. When processing returns, the backend fails to filter or escape the goodsName parameter, directly concatenating it into the order log description; the frontend subsequently renders this content using v-html. An attacker with product creation privileges can inject a malicious JavaScript payload, causing unauthorized code execution when an administrator views the order logs. Join the discussion | CVE Database V5 | 09/09/2026, 00:00:00 UTC Added: 09/09/2026, 20:52:42 UTC |
CVE-2026-71802: n/aCVE-2026-71802 0 A stored Cross-Site Scripting (XSS) vulnerability exists in the announcement preview component of REBUILD 4.4.3. Although the announcement content undergoes HTML escaping on the server side, the client-side preview code reverses the escaped entities using jQuery's `html().text()` method and subsequently injects the result into the DOM. An administrator or attacker capable of controlling the announcement content can exploit this vulnerability to execute arbitrary JavaScript code in the browsers of users viewing the affected pages "which may include the dashboard, activity feed, or login page, depending on the announcement's visibility settings. Join the discussion | CVE Database V5 | 09/09/2026, 00:00:00 UTC Added: 09/09/2026, 20:52:42 UTC |
CVE-2026-79387: n/aCVE-2026-79387 0 SQL injection vulnerability in PbootCMS versions 3.2.0 through 3.2.5 allows an authenticated user to modify arbitrary user account fields (including passwords and roles) via crafted parameters to the User/mod interface, enabling account takeover. Join the discussion | CVE Database V5 | 09/09/2026, 00:00:00 UTC Added: 09/09/2026, 20:52:42 UTC |
CVE-2026-79522: n/aCVE-2026-79522 0 CVE-2026-79522 is an out-of-bounds read vulnerability in the gf_dm_get_chunk_data function of GPAC version 26.07.0. This flaw can be triggered by sending a crafted HTTP request, potentially causing a denial of service (DoS) condition. The issue has been fixed in commit 2fd5a06ab226767900fd86edb5a1e8bfc1010640. The vulnerability has a CVSS 3.1 base score of 6.5, indicating a medium severity level. Join the discussion | CVE Database V5 | 09/09/2026, 00:00:00 UTC Added: 09/09/2026, 20:37:52 UTC |
CVE-2026-79514: n/aCVE-2026-79514 0 CVE-2026-79514 is an out-of-bounds read vulnerability in the gf_dm_data_received function of GPAC version 26.07.0. This flaw can be triggered by sending a crafted HTTP request, potentially causing a Denial of Service (DoS) condition. The issue has been fixed in commit 2fd5a06ab226767900fd86edb5a1e8bfc1010640. The vulnerability has a CVSS score of 6.5, indicating medium severity. Join the discussion | CVE Database V5 | 09/09/2026, 00:00:00 UTC Added: 09/09/2026, 20:37:52 UTC |
CVE-2026-79513: n/aCVE-2026-79513 0 A divide-by-zero vulnerability exists in the gf_dash_get_timeline_duration function of GPAC version prior to 26.07.0. This flaw allows an attacker to cause a Denial of Service (DoS) by providing a specially crafted MPD SegmentTimeline. The issue has been fixed in a later commit identified as 2fd5a06ab226767900fd86edb5a1e8bfc1010640. Join the discussion | CVE Database V5 | 09/09/2026, 00:00:00 UTC Added: 09/09/2026, 20:37:52 UTC |
CVE-2026-79515: n/aCVE-2026-79515 0 CVE-2026-79515 is an out-of-bounds read vulnerability in the stbtt_GetGlyphShape component of nothings stb library. This flaw can be triggered by processing a crafted TrueType Font (TTF) file, potentially causing a Denial of Service (DoS) condition. The vulnerability has a medium severity rating with a CVSS score of 4.3. No specific affected versions or patches are currently documented. There are no known exploits in the wild at this time. Join the discussion | CVE Database V5 | 09/09/2026, 00:00:00 UTC Added: 09/09/2026, 20:37:52 UTC |
CVE-2026-71801: n/aCVE-2026-71801 0 s-pms SPMS-Server through version 1.0 contains a hardcoded default access token secret in its core configuration file that is not removed or overridden in production. This flaw allows a remote, unauthenticated attacker to forge valid administrative session tokens, bypassing authentication and gaining full unauthorized access to protected backend APIs. Join the discussion | CVE Database V5 | 09/09/2026, 00:00:00 UTC Added: 09/09/2026, 20:37:52 UTC |
Showing 1 to 10 of 19278 results