Skip to main content

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Package: pkg:npm/@opennextjs/cloudflare

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

A flaw was found in gss-ntlmssp. A memory leak occurs in the NTLM target-info parser when a crafted NTLM CHALLENGE message contains duplicated string-valued AV_PAIR entries. The parser allocates memory for each string value but does not free the previous allocation when the same AV_PAIR type appears more than once, leaking the earlier allocation. A malicious or man-in-the-middle server can exploit this to cause gradual memory exhaustion on the client during NTLM authentication, leading to a denial of service.

Join the discussion

Japan's Digital Agency suffered a data breach affecting approximately 240,000 individuals due to exploitation of a vulnerability in a VPN product. The attackers accessed personal information including names, email addresses, phone numbers, and workplace-related addresses. The breach was discovered in late June 2026 and involved unauthorized use of a maintenance employee's account. No sensitive information such as identification numbers or financial data was compromised. The agency blocked external access to the affected server and suspended the compromised account. The exploited VPN vulnerability was publicly disclosed prior to the attack. No other systems or general public information were affected.

HighBreach
Join the discussion

CVE-2026-89308 is a critical unauthenticated OS command injection vulnerability in the ping.php endpoint of TREXOM TrxTimeATTENDANCE. This flaw allows remote attackers to execute arbitrary commands on the underlying operating system, leading to remote code execution. The vulnerability affects versions from 1.0.5 up to but not including 1.9.6. It has a high CVSS 4.0 score of 9.3, indicating severe impact with no required privileges or user interaction. No patch or vendor advisory is currently provided, and no known exploits are reported in the wild.

Join the discussion

evolution-api through 2.3.7 contains an incorrect array comparison in the metricsIPWhitelist middleware that always evaluates to false, allowing unauthenticated access to the /metrics endpoint. Attackers can bypass IP whitelist restrictions to access sensitive metrics disclosing server version, database client name, configured server URL, and WhatsApp instance details.

Join the discussion

CVE-2026-91996 is a high-severity vulnerability in dromara lamp-cloud up to version 5.10.0. The application improperly allows anonymous access to the path pattern /*/anno/**, enabling unauthenticated attackers to read the full JVM system property map. By sending POST requests to /defGenProject/anno/getProperties, attackers can retrieve sensitive information such as JVM classpath, filesystem paths, operating system details, and startup secrets.

Join the discussion

pig versions before 4.1.0 have an authentication bypass vulnerability in the /register/password endpoint. This flaw allows remote attackers to bypass password verification and change any account's password, including the admin account, without knowing the current password. Exploitation grants full administrative control over the affected system.

Join the discussion

Semaphore UI versions up to 2.19.12 have a missing authorization vulnerability in the GetMustCanMiddleware that exempts GET and HEAD requests from project resource permission checks. This allows attackers with guest or task_runner roles to read all project environments, including sensitive plaintext secrets, credentials, and passwords via GET requests to the environment endpoint.

Join the discussion

Jpom versions up to 2.11.12 contain an authorization bypass vulnerability where workspace ownership is not properly validated on the /build/branch-list endpoint. This flaw allows authenticated users to access repositories belonging to other workspaces by submitting repository identifiers from those workspaces. Exploitation enables attackers to enumerate repository existence, identify repository types, and execute git ls-remote commands using credentials stored in other workspaces.

Join the discussion

Apple released major updates iOS 27 and macOS Golden Gate 27 that patch over 200 security vulnerabilities affecting kernel and multiple platform components. These flaws could lead to memory corruption, privilege escalation, system termination, and information leaks. The updates also fix a medium-severity Samba heap-based buffer overflow from 2022. No active exploitation has been reported. Users are advised to update promptly to benefit from these fixes.

HighVulnerability#macos#ios
Join the discussion

CVE-2026-1759 is a vulnerability in Secomea GateManager involving improper handling of insufficient permissions or privileges, which allows privilege escalation. The issue affects versions 11.5;0 and 11.4.625515072:0. It has been fixed in versions 11.6 and 11.4.626194074 and above. The vulnerability has a CVSS 3.1 score of 6.5, indicating a medium severity level.

Join the discussion

Showing 1 to 10 of 131774 results

Filters:Package: pkg:npm/@opennextjs/cloudflare
Page 1 of 13178
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses