Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

LG to Ban Residential Proxies from Smart TV Apps
0

LG Electronics USA plans to suspend smart TV apps that convert televisions into always-on residential proxy nodes. Research found that over 42% of apps on LG's webOS store include SDKs enabling unknown third parties to route internet traffic through users' TVs. LG is working with developers to remove these proxy features and will suspend non-compliant apps. The issue arises from developers embedding residential proxy SDKs to monetize apps by turning user devices into proxy nodes rented to third parties. LG is enhancing its app review process to prevent such uses going forward.

LowVulnerability#web#rce
Join the discussion
CVE-2026-56844: CWE-22 Path Traversal in Veeam Backup and ReplicationCVE-2026-56844
0

CVE-2026-56844 is a high-severity vulnerability in the Veeam Updater component of the Veeam Backup and Replication software appliance. It involves a path traversal flaw (CWE-22) that could allow a local user with elevated privileges to escalate to root-level access on the underlying operating system. This vulnerability does not require user interaction and has a low attack complexity. No patch or official remediation has been confirmed yet.

Join the discussion
CVE-2026-16492: OS Command Injection in umijs umiCVE-2026-16492
0

A command injection vulnerability exists in the umijs umi package up to version 4.6.63 in the git.getFileCreateInfo function of the GIT File Helper component. This vulnerability allows an attacker with limited privileges to execute arbitrary OS commands due to insufficient input handling. The issue is fixed in version 4.6.64. The vulnerability has a medium severity rating with a CVSS score of 5.1.

Join the discussion
CVE-2026-16490: SQL Injection in itsourcecode Hospital Management SystemCVE-2026-16490
0

CVE-2026-16490 is a medium severity SQL injection vulnerability in itsourcecode Hospital Management System version 1.0. The flaw exists in the /prescription.php file where manipulation of the 'editid' parameter allows remote attackers to perform SQL injection. The vulnerability has a CVSS 4.0 base score of 5.3. No official patch or remediation guidance is currently available from the vendor. Exploit code has been publicly released, but no known active exploitation in the wild has been reported.

Join the discussion
Immutabl: Hash-collision algorithmic complexity denial of service in Immutable.Map/Set (CVE-2026-59880)CVE-2026-59880
0

Immutable.js versions through 5.1.7 contain a hash-collision algorithmic complexity vulnerability in Immutable.Map and Immutable.Set. The deterministic, public string hash function allows attackers controlling keys to craft many colliding keys that degrade insertion and lookup performance from O(1) to O(n), causing CPU exhaustion and denial of service in single-threaded runtimes like Node.js. The issue is fixed in version 5.1.8 by introducing a seeded secondary hash to index large collision buckets. Applications ingesting untrusted object keys into Immutable structures are vulnerable, while those only using attacker input as values under fixed keys are not affected.

Join the discussion
pyasn1: Quadratic complexity in OBJECT IDENTIFIER and RELATIVE-OID processing allows denial of service (CVE-2026-59885)CVE-2026-59885
0

pyasn1 versions prior to 0.6.4 contain a vulnerability in the BER/CER/DER decoders and encoders for OBJECT IDENTIFIER and RELATIVE-OID values. The processing of these values exhibits quadratic time complexity relative to the number of arcs, allowing a crafted payload with many arcs to cause significant CPU consumption. This can lead to denial of service in applications decoding untrusted ASN.1 data such as certificates, LDAP, SNMP, or Kerberos. The issue is fixed in pyasn1 version 0.6.4 by improving the arc accumulation to linear time.

Join the discussion
pyasn1: Uncontrolled resource consumption when converting decoded REAL values (CVE-2026-59886)CVE-2026-59886
0

pyasn1 versions prior to 0.6.4 contain a vulnerability in the univ.Real type where converting decoded REAL values to Python floats can cause uncontrolled resource consumption. This occurs because very large exponents in BER/CER/DER-encoded REAL values trigger expensive big-integer exponentiation, leading to excessive CPU and memory use. The issue affects float conversions including prettyPrint(), str(), comparisons, arithmetic, and explicit float() calls on decoded REAL values. Applications decoding untrusted ASN.1 data that then convert or print these REAL values are vulnerable to denial of service. The vulnerability is fixed in pyasn1 version 0.6.4. Avoid converting or printing REAL objects from untrusted sources as a workaround.

Join the discussion
Gitea: Repository Migration Follows Git HTTP Redirects After URL Allow/Block Validation, Enabling Internal Git Repository Exfiltration (CVE-2026-57894)CVE-2026-57894
0

Gitea versions prior to 1.27.0 contain a vulnerability where repository migration URLs are validated before cloning, but the Git client follows HTTP redirects without restriction. This allows a low-privileged authenticated user to bypass URL allow/block policies by submitting a public Git URL that redirects to an internal or otherwise blocked Git repository. The Git client then fetches repository data from the redirected internal endpoint, enabling exfiltration of internal Git repositories. The issue affects migration and mirror fetch operations, potentially exposing sensitive internal repositories and secrets. The vulnerability is high severity for internet-facing instances with migrations enabled and can escalate to critical if sensitive internal data is exposed. No direct unauthenticated exploitation or remote code execution is confirmed.

Join the discussion
Picklescan is missing detection when calling built-in python ensurepip._run_pip (CVE-2025-71344)CVE-2025-71344
0

Picklescan versions prior to 0.0.30 fail to detect malicious pickle files that exploit the built-in Python function ensurepip._run_pip. This allows attackers to embed and execute arbitrary code when such pickle files are loaded, bypassing Picklescan's detection. The vulnerability impacts users relying on Picklescan to validate pickle files, including those embedded in PyTorch models. This can facilitate supply chain attacks by distributing infected pickle files across machine learning models, APIs, or saved Python objects.

Join the discussion
@vitest/browser: Browser Mode provider commands bypass the file-access permission gate
0

A vulnerability in @vitest/browser's Browser Mode allows certain built-in commands to bypass the file-access permission gate. These commands can read, write, or delete files anywhere accessible by the Vitest process, ignoring the allowWrite flag and path confinement. This is particularly risky when the Browser Mode API is exposed beyond localhost, enabling arbitrary file read and modification by untrusted clients. The vulnerability affects versions >=4.0.0 <4.1.10 and <3.2.7. A fix is planned to enforce allowWrite checks and restrict paths to the project root.

Join the discussion

Showing 1 to 10 of 21021 results

Filters:Package: pkg:npm/@nevware21/ts-utils
Page 1 of 2103
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses