Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

OffsetInspect v3.0.0 – track how Defender signature updates shift detection boundaries across a corpus [PowerShell, MIT]
0

OffsetInspect v3.0.0 – track how Defender signature updates shift detection boundaries across a corpus [PowerShell, MIT] Source: https://github.com/warpedatom/OffsetInspect

Join the discussion
Browser-Based P2P Messaging App
0

Browser-Based P2P Messaging App Source: https://enkrypted.chat/

Join the discussion
CVE-2026-57990: CWE-552: Files or Directories Accessible to External Parties in Microsoft Microsoft Edge (Chromium-based)CVE-2026-57990
0

Files or directories accessible to external parties in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.

Join the discussion
CVE-2026-57989: CWE-346: Origin Validation Error in Microsoft Microsoft Edge (Chromium-based)CVE-2026-57989
0

Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.

Join the discussion
CVE-2026-57978: CWE-346: Origin Validation Error in Microsoft Microsoft Edge (Chromium-based)CVE-2026-57978
0

CVE-2026-57978 is an origin validation error vulnerability in Microsoft Edge (Chromium-based) that allows an unauthorized attacker to perform spoofing over a network. The vulnerability has a medium severity with a CVSS score of 5.4. An official fix is available from Microsoft to address this issue.

Join the discussion
PoCumentary, an agent-friendly tool for recording PoCs
0

PoCumentary is an open-source command-line tool designed to help security researchers and developers create polished, narrated screen recordings of proof-of-concept (PoC) exploits. It automates arranging multiple terminal panes, coordinating demo steps, recording workflows, and synchronizing captions or narration tied to actual demo events. The tool aims to improve the clarity, reproducibility, and presentation of technical findings. There is no indication that PoCumentary itself introduces a security vulnerability or threat.

Join the discussion
Scans for ESAFENET CDG 3 Document Management System Weak Logins, (Sun, Jul 26th)
0

ESAFENET's CDG (Content Data Guard) Document Management System, primarily targeting the Chinese market, suffers from basic security vulnerabilities including SQL Injection, cross-site scripting (XSS), and the use of well-known default passwords. Recent scans have been detected targeting these weak default credentials, which are publicly documented and included in exploit templates. Although the product aims to secure document management and prevent data leakage, these fundamental security issues undermine its effectiveness. No specific affected versions or patches are publicly detailed.

MediumVulnerability#xss
Join the discussion
CVE-2026-17497: CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in codexu NoteGenCVE-2026-17497
0

NoteGen versions prior to 0.32.0 include a vulnerability where the Tauri shell plugin grants shell:allow-execute capability for bash, python, and python3 with arbitrary arguments by default. This allows JavaScript running in the application's webview to execute operating system commands with the privileges of the NoteGen process. If an attacker can execute scripts in the webview (e.g., via cross-site scripting), they can achieve full remote code execution on the user's machine.

Join the discussion
CVE-2026-17496: CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in codexu NoteGenCVE-2026-17496
0

NoteGen versions prior to 0.32.0 contain a cross-site scripting (XSS) vulnerability due to improper sanitization of AI chat responses rendered with markdown-it configured to allow HTML. The application injects this content into the DOM using dangerouslySetInnerHTML without sanitization and with a null Content Security Policy (CSP). Malicious input that influences the AI model's response can cause execution of arbitrary JavaScript in the privileged Tauri webview context when users view the chat response.

Join the discussion
GitHub, PyPI add time-absed defenses against supply chain attacks
0

GitHub and PyPI have introduced time-based defenses in their dependency management and package publishing processes to mitigate supply chain attacks. GitHub's Dependabot now enforces a default 72-hour cooldown before automatically updating dependencies, reducing the risk of quickly adopting malicious packages. PyPI blocks maintainers from adding new files to package releases older than 14 days to prevent release poisoning. These measures respond to recent high-profile supply chain attacks and aim to limit the impact of compromised packages or publishing tokens.

MediumVulnerability#python
Join the discussion

Showing 1 to 10 of 20481 results

Filters:Package: pkg:npm/@libp2p/kad-dht
Page 1 of 2049
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses