Skip to main content

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Package: pkg:npm/@payloadcms/graphql

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

A privilege escalation flaw was found in the scan_mysql actor of leapp-upgrade-el9toel10 (provided by leapp-repository). During RHEL 9 to RHEL 10 upgrades, the actor runs: mysqld --validate-config --log-error-verbosity=2 directly as root in the Leapp actor context, bypassing the packaged MySQL systemd unit that normally starts the daemon as User=mysql. A process compromised as the mysql OS identity can write a version-2 persisted configuration (mysqld-auto.cnf) and a malicious shared object into /var/lib/mysql (a directory owned by mysql). That persisted map can set plugin_dir to /var/lib/mysql and early_plugin_load (or related loader options such as plugin_load / plugin_load_add) so MySQL loads the attacker-controlled object during configuration validation. Plugin loading can reach dlopen() before MySQL’s runtime-user check and before plugin-symbol validation. When an administrator subsequently runs the documented Leapp preupgrade or upgrade workflow, attacker-controlled code can execute as UID 0 with a full capability set in an unconfined SELinux domain (unconfined_t). The attack does not require write access to the default system plugin path under /usr; redirecting plugin_dir via mysql-owned persisted state is sufficient. Ordinary SQL privileges alone (including highly privileged SQL accounts) are not a sufficient startpoint — OS-level execution as the mysql service identity is required, plus later administrator invocation of Leapp.

Join the discussion

A security flaw has been discovered in GNU Binutils 2.47. This affects the function _bfd_elf_eh_frame_section_offset of the file bfd/elf-eh-frame.c of the component Eh Frame Handler. Performing a manipulation results in null pointer dereference. The attack must be initiated from a local position. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through a bug report but has not responded yet.

Join the discussion
0

CVE-2026-91091 is a medium severity memory corruption vulnerability in the GPAC software, specifically in the function gf_node_list_insert_child within the Node Insertion component. This vulnerability affects GPAC versions up to commit f1219cde. The flaw allows remote attackers to cause memory corruption, and public exploit code is available. The issue is resolved by upgrading to GPAC version abi-16.23.

Join the discussion

Cisco has released a patch for a critical zero-day vulnerability in its Secure Email Gateway product that has been actively exploited by threat actors. Customers are urged to apply the patch promptly to mitigate the risk. No detailed technical information or CVSS score is available at this time.

Join the discussion
0

CVE-2026-91090 is a stack-based buffer overflow vulnerability in the GPAC multimedia framework affecting the function gf_node_activate_ex in scenegraph/base_scenegraph.c. The issue affects GPAC versions up to commit f1219cde. Exploitation requires local access and involves low complexity with limited privileges. The vulnerability has a low CVSS score of 2.4. Upgrading to version abi-16.23 resolves the issue.

Join the discussion
0

CVE-2026-91089 is a use-after-free vulnerability in the GPAC multimedia framework affecting the function gf_node_get_name_and_id in scenegraph/base_scenegraph.c. This vulnerability allows remote attackers to exploit the flaw, potentially leading to memory corruption. An exploit has been publicly disclosed. The issue is addressed by upgrading to GPAC version abi-16.23, which contains the patch identified by commit 49dee5cad329cfed310c1682703df7daa47df31a.

Join the discussion

CVE-2026-91778 is a high-severity vulnerability in Octopus Deploy's Octopus Server where users with certain scoped permissions can execute arbitrary scripts on a worker without proper authorization. This occurs due to incorrect permission validation during script execution, allowing actions beyond the user's intended privileges.

Join the discussion

The Job Postings plugin for WordPress, developed by blueglassch, contains a stored cross-site scripting (XSS) vulnerability in the 'position_button' parameter. This affects all versions up to and including 2.8.1. Authenticated users with contributor-level access or higher can inject malicious scripts that execute when other users view the affected pages. The vulnerability arises from insufficient input sanitization and output escaping.

Join the discussion
0

CVE-2026-91088 is a heap-based buffer overflow vulnerability in the GPAC project's URL Handler component, specifically in the gf_url_concatenate_ex function of utils/url.c. This vulnerability affects GPAC versions up to commit f1219cde. Exploitation requires local access with low privileges and user interaction. The issue is addressed by upgrading to GPAC version abi-16.23.

Join the discussion
0

CVE-2026-91087 is a use-after-free vulnerability in the GPAC multimedia framework affecting the gf_mo_get_od_id function in compositor/media_object.c. This flaw can be triggered remotely and may lead to memory corruption. An exploit is publicly available. The issue is resolved by upgrading to GPAC version abi-16.24.

Join the discussion

Showing 1 to 10 of 131725 results

Filters:Package: pkg:npm/@payloadcms/graphql
Page 1 of 13173
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses