Skip to main content

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Package: pkg:npm/@pensar/apex

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

A vulnerability was detected in GNU Binutils 2.47. Affected by this vulnerability is the function elf_x86_allocate_dynrelocs of the file bfd/elfxx-x86.c of the component Dynamic Relocation Allocation. The manipulation results in null pointer dereference. The attack requires a local approach. The exploit is now public and may be used. Upgrading to version 2.48 addresses this issue. The patch is identified as d1268210b6f6/471130b39c0/283d3198bed/0a84e560216/a692a633d40. Upgrading the affected component is recommended.

Join the discussion

Hidden functionality issue exists in FF-RFI079I4 and FF-RFI078I4, which may allow a user who can log in via SSH and access the enable mode on the product to execute arbitrary OS commands.

Join the discussion

Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in FF-RFI079I4 and FF-RFI078I4. A user who can log in to the product's M-Plane (NETCONF) may execute arbitrary OS commands.

Join the discussion

Stack-based buffer overflow vulnerability in Samsung Opensource rLottie allows attackers to overflow buffers, leading to memory corruption when rendering crafted vector animations. This issue affects rLottie: 480a2ad0c5d2e45458c545b8213279e9e8b71e39.

Join the discussion

A security vulnerability has been detected in GNU Binutils 2.47. Affected is the function elf_x86_64_common_section_index of the file bfd/elf64-x86-64.c of the component ELF Section Handler. The manipulation leads to null pointer dereference. The attack needs to be performed locally. The exploit has been disclosed publicly and may be used. Upgrading to version 2.48 is able to address this issue. The identifier of the patch is 7322e9bc30cb282575a701c307851fd3d66fee68. It is suggested to upgrade the affected component.

Join the discussion

Microsoft has acknowledged that the September 2026 security update KB5002914 for Excel causes copy and paste operations to silently fail for some users. This issue affects the usability of Excel but does not indicate a security vulnerability or exploitation. No affected versions or patch status details are provided.

LowNews
Join the discussion

CVE-2026-91780 is a medium severity vulnerability in GNU Binutils 2.47 involving a null pointer dereference in the elf_link_add_object_symbols function within bfd/elflink.c. The flaw requires local access to exploit and could lead to a denial of service or application crash. Public exploit code is available, but no vendor response or patch has been issued yet.

Join the discussion

CVE-2026-75092 is a privilege escalation vulnerability in the leapp-upgrade-el9toel10 tool used during Red Hat Enterprise Linux upgrades from version 9 to 10. The flaw arises because the scan_mysql actor runs the MySQL daemon validation command as root, bypassing normal user restrictions. An attacker with OS-level access as the mysql user can place malicious plugins in a MySQL-owned directory, which are then loaded during the upgrade process with root privileges. This allows arbitrary code execution as root in an unconfined SELinux domain when an administrator runs the upgrade workflow. The vulnerability requires prior compromise of the mysql OS identity and administrator invocation of the upgrade process. No patch or mitigation currently meets Red Hat's criteria for deployment.

Join the discussion

CVE-2026-91779 is a medium severity vulnerability in GNU Binutils 2.47 affecting the Eh Frame Handler component. It involves a null pointer dereference in the _bfd_elf_eh_frame_section_offset function, which can be triggered by a local attacker. The vulnerability has a CVSS score of 4.8 and public exploit code is available. The vendor has not yet responded or issued a patch.

Join the discussion
0

CVE-2026-91091 is a medium severity memory corruption vulnerability in the GPAC software, specifically in the function gf_node_list_insert_child within the Node Insertion component. This vulnerability affects GPAC versions up to commit f1219cde. The flaw allows remote attackers to cause memory corruption, and public exploit code is available. The issue is resolved by upgrading to GPAC version abi-16.23.

Join the discussion

Showing 1 to 10 of 131732 results

Filters:Package: pkg:npm/@pensar/apex
Page 1 of 13174
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses