Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
Cisco has released a patch for a critical zero-day vulnerability in its Secure Email Gateway product that has been actively exploited by threat actors. Customers are urged to apply the patch promptly to mitigate the risk. No detailed technical information or CVSS score is available at this time. Join the discussion | Bleeping Computer | 09/15/2026, 07:31:09 UTC Added: 09/15/2026, 07:31:47 UTC |
CVE-2026-91089: Use After Free in GPACCVE-2026-91089 0 A vulnerability was found in GPAC up to f1219cde. Impacted is the function gf_node_get_name_and_id of the file scenegraph/base_scenegraph.c. The manipulation results in use after free. It is possible to launch the attack remotely. The exploit has been made public and could be used. Upgrading to version abi-16.23 is recommended to address this issue. The patch is identified as 49dee5cad329cfed310c1682703df7daa47df31a. You should upgrade the affected component. Join the discussion | CVE Database V5 | 09/15/2026, 07:15:09 UTC Added: 09/15/2026, 07:32:17 UTC |
In affected versions of Octopus Server, users with certain scoped permission sets could execute arbitrary scripts on a worker (including the Octopus Server built-in worker). Incorrect permission validation during script execution would allow the script to execute without the user possessing the required authorisation. Join the discussion | CVE Database V5 | 09/15/2026, 07:05:53 UTC Added: 09/15/2026, 07:32:17 UTC |
0 The Job Postings plugin for WordPress, developed by blueglassch, contains a stored cross-site scripting (XSS) vulnerability in the 'position_button' parameter. This affects all versions up to and including 2.8.1. Authenticated users with contributor-level access or higher can inject malicious scripts that execute when other users view the affected pages. The vulnerability arises from insufficient input sanitization and output escaping. Join the discussion | CVE Database V5 | 09/15/2026, 07:03:06 UTC Added: 09/15/2026, 07:17:17 UTC |
0 CVE-2026-91088 is a heap-based buffer overflow vulnerability in the GPAC project's URL Handler component, specifically in the gf_url_concatenate_ex function of utils/url.c. This vulnerability affects GPAC versions up to commit f1219cde. Exploitation requires local access with low privileges and user interaction. The issue is addressed by upgrading to GPAC version abi-16.23. Join the discussion | CVE Database V5 | 09/15/2026, 07:00:15 UTC Added: 09/15/2026, 07:17:17 UTC |
0 CVE-2026-91087 is a use-after-free vulnerability in the GPAC multimedia framework affecting the gf_mo_get_od_id function in compositor/media_object.c. This flaw can be triggered remotely and may lead to memory corruption. An exploit is publicly available. The issue is resolved by upgrading to GPAC version abi-16.24. Join the discussion | CVE Database V5 | 09/15/2026, 06:45:12 UTC Added: 09/15/2026, 07:02:06 UTC |
0 CVE-2026-91086 is a heap-based buffer overflow vulnerability in the GPAC MPEG Video Reframer component, specifically in the mpgviddmx_process function. This vulnerability affects GPAC versions up to commit f1219cde. The flaw can be exploited remotely and has been publicly disclosed. A patch is available in version abi-16.23, which addresses this issue. Users are advised to upgrade to this version to mitigate the risk. Join the discussion | CVE Database V5 | 09/15/2026, 06:30:16 UTC Added: 09/15/2026, 06:47:17 UTC |
0 CVE-2026-91005 is a medium severity vulnerability in SourceCodester Online Faculty Clearance System version 1.0. It involves an unrestricted file upload flaw in the move_uploaded_file function within production/edit_picture.php, allowing remote attackers to upload arbitrary files. An exploit for this vulnerability has been publicly disclosed. Join the discussion | CVE Database V5 | 09/15/2026, 06:15:12 UTC Added: 09/15/2026, 06:47:17 UTC |
The Eventin WordPress plugin up to version 4.1.23 contains a privilege escalation vulnerability. The flaw arises because the plugin's permission management function grants all capabilities to the user with ID 1 unconditionally, regardless of their assigned role. This allows an attacker with user ID 1 but a lower-privilege role to gain administrator-level permissions, potentially leading to full site takeover and remote code execution via plugin or theme editors. The vulnerability is only exploitable if the user ID 1 account has been demoted from administrator, which is a common security hardening practice. Default installations where user ID 1 remains an administrator are not affected by privilege escalation. Join the discussion | CVE Database V5 | 09/15/2026, 06:07:31 UTC Added: 09/15/2026, 06:47:17 UTC |
The Eventin WordPress plugin (up to version 4.1.23) contains a stored cross-site scripting (XSS) vulnerability via the 'etn_shedule_objective' schedule_slot parameter. Authenticated users with contributor-level access or higher can inject malicious scripts that execute when other users view the affected pages. This vulnerability arises from insufficient input sanitization and output escaping. Join the discussion | CVE Database V5 | 09/15/2026, 06:07:31 UTC Added: 09/15/2026, 06:47:17 UTC |
Showing 1 to 10 of 131721 results