Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

CVE-2026-79516: n/aCVE-2026-79516
0

An out-of-bounds read in the stbsp_vsnprintf function (stb_sprintf.h) of nothings stb commit 31c1ad3 allows attackers to cause a Denial of Service (DoS) via sending a crafted input.

Join the discussion
CVE-2026-71808: n/aCVE-2026-71808
0

A SQL Injection vulnerability in Siam Ordering (siam-server) 1.0.0 allows remote authenticated attackers to execute arbitrary SQL commands via the ${} string concatenation in AdminMapper.java and multiple other Mapper files (including MerchantWithdrawRecordMapper.java and MemberWithdrawRecordMapper.java).

Join the discussion
CVE-2026-71803: n/aCVE-2026-71803
0

money-pos 1.0 contains a stored Cross-Site Scripting (XSS) vulnerability. When processing returns, the backend fails to filter or escape the goodsName parameter, directly concatenating it into the order log description; the frontend subsequently renders this content using v-html. An attacker with product creation privileges can inject a malicious JavaScript payload, causing unauthorized code execution when an administrator views the order logs.

Join the discussion
CVE-2026-71802: n/aCVE-2026-71802
0

A stored Cross-Site Scripting (XSS) vulnerability exists in the announcement preview component of REBUILD 4.4.3. Although the announcement content undergoes HTML escaping on the server side, the client-side preview code reverses the escaped entities using jQuery's `html().text()` method and subsequently injects the result into the DOM. An administrator or attacker capable of controlling the announcement content can exploit this vulnerability to execute arbitrary JavaScript code in the browsers of users viewing the affected pages "which may include the dashboard, activity feed, or login page, depending on the announcement's visibility settings.

Join the discussion
CVE-2026-79387: n/aCVE-2026-79387
0

SQL injection vulnerability in PbootCMS versions 3.2.0 through 3.2.5 allows an authenticated user to modify arbitrary user account fields (including passwords and roles) via crafted parameters to the User/mod interface, enabling account takeover.

Join the discussion
CVE-2026-79522: n/aCVE-2026-79522
0

CVE-2026-79522 is an out-of-bounds read vulnerability in the gf_dm_get_chunk_data function of GPAC version 26.07.0. This flaw can be triggered by sending a crafted HTTP request, potentially causing a denial of service (DoS) condition. The issue has been fixed in commit 2fd5a06ab226767900fd86edb5a1e8bfc1010640. The vulnerability has a CVSS 3.1 base score of 6.5, indicating a medium severity level.

Join the discussion
CVE-2026-79514: n/aCVE-2026-79514
0

CVE-2026-79514 is an out-of-bounds read vulnerability in the gf_dm_data_received function of GPAC version 26.07.0. This flaw can be triggered by sending a crafted HTTP request, potentially causing a Denial of Service (DoS) condition. The issue has been fixed in commit 2fd5a06ab226767900fd86edb5a1e8bfc1010640. The vulnerability has a CVSS score of 6.5, indicating medium severity.

Join the discussion
CVE-2026-79513: n/aCVE-2026-79513
0

A divide-by-zero vulnerability exists in the gf_dash_get_timeline_duration function of GPAC version prior to 26.07.0. This flaw allows an attacker to cause a Denial of Service (DoS) by providing a specially crafted MPD SegmentTimeline. The issue has been fixed in a later commit identified as 2fd5a06ab226767900fd86edb5a1e8bfc1010640.

Join the discussion
CVE-2026-79515: n/aCVE-2026-79515
0

CVE-2026-79515 is an out-of-bounds read vulnerability in the stbtt_GetGlyphShape component of nothings stb library. This flaw can be triggered by processing a crafted TrueType Font (TTF) file, potentially causing a Denial of Service (DoS) condition. The vulnerability has a medium severity rating with a CVSS score of 4.3. No specific affected versions or patches are currently documented. There are no known exploits in the wild at this time.

Join the discussion
CVE-2026-71801: n/aCVE-2026-71801
0

s-pms SPMS-Server through version 1.0 contains a hardcoded default access token secret in its core configuration file that is not removed or overridden in production. This flaw allows a remote, unauthenticated attacker to forge valid administrative session tokens, bypassing authentication and gaining full unauthorized access to protected backend APIs.

Join the discussion

Showing 1 to 10 of 19278 results

Filters:Package: pkg:npm/@libp2p/kad-dht
Page 1 of 1928
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses