Skip to main content

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Package: pkg:npm/@microsoft/kiota-http-fetchlibrary

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

ManageEngine DataSecurity Plus versions before 6310 are vulnerable to an authenticated SQL injection vulnerability, allowing an authenticated technician to execute arbitrary SQL queries through the Reports module.

Join the discussion

ManageEngine DataSecurity Plus versions before 6310 are vulnerable to an agent authentication bypass, allowing unenrolled agents to send requests without proper authentication.

Join the discussion

This entry is a daily security news update from the SANS Internet Storm Center (ISC) titled 'ISC Stormcast For Friday, September 18th, 2026.' It does not contain any specific information about a security threat, vulnerability, or exploit.

LowNews
Join the discussion
0

CVE-2026-93331 is a medium severity vulnerability in GPAC version 26.08-DEV affecting the RTP Depacketizer component. It involves an out-of-bounds read in the function gf_rtp_parse_ttxt due to improper handling of the argument size. The vulnerability can be exploited remotely without authentication. Upgrading to version abi-16.26 resolves the issue.

Join the discussion

CVE-2026-93312 is a medium severity vulnerability in Freedesktop Poppler version 26.07.0. It involves a null pointer dereference in the JBIG2Stream::rewind function within the poppler/JBIG2Stream.cc file. This flaw can be triggered remotely and requires user interaction. An exploit has been published. Upgrading to Poppler version 26.08.0 addresses this issue.

Join the discussion
0

CVE-2026-93311 is an integer overflow vulnerability in Freedesktop Poppler version 26.07.0. It affects the SampledFunction::SampledFunction function in the poppler/Function.cc file, where manipulation of the BitsPerSample argument can cause an integer overflow. The vulnerability can be exploited remotely and public exploit code is available. The project has been informed but has not yet responded or released a fix.

Join the discussion

NASA CryptoLib version 1.5.0 has an authentication downgrade vulnerability in its Telecommand receive path. The vulnerability arises because the receiver selects the Security Association (SA) based only on the SPI field in the incoming frame without verifying that the SA is authorized for the frame's GVCID. This flaw can allow unauthorized use of critical functions due to missing authentication checks.

Join the discussion

A vulnerability was identified in O-RAN-SC SMO OAM 2025-06-10. This affects an unknown part of the component VES Collector. The manipulation leads to allocation of resources. Remote exploitation of the attack is possible. The exploit is publicly available and might be used. The project was informed of the problem early through a bug report but has not responded yet.

Join the discussion

A vulnerability was determined in O-RAN-SC SMO OAM 2025-06-10. Affected by this issue is some unknown functionality of the component VES Collector. Executing a manipulation can lead to allocation of resources. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through a bug report but has not responded yet.

Join the discussion

The Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.6.9 via the set_customer_object due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to enumerate arbitrary customer records and disclose personally identifiable information - including first name, last name, email address, and phone number - by iterating the customer[id] parameter. This issue is exploitable only when the site is configured with customer authentication disabled (guest checkout enabled).

Join the discussion

Showing 1 to 10 of 135462 results

Filters:Package: pkg:npm/@microsoft/kiota-http-fetchlibrary
Page 1 of 13547
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses