Skip to main content

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Package: pkg:npm/@progress/kendo-vue-charts

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

ExtUtils::Typemaps::STL::List versions before 1.07 for Perl contain an integer underflow vulnerability that causes allocation of a 32 GiB array when processing an empty list. This occurs because the output typemaps call av_extend(av, len-1), which underflows when len is zero, leading to excessive memory allocation and potential exhaustion. A similar issue was previously fixed in ExtUtils::Typemaps::STL::Vector version 1.05.

Join the discussion
0

CVE-2026-107373 is an out-of-bounds read vulnerability in ExtUtils::Typemaps::STL::String versions before 1.06 for Perl. The vulnerability arises because the typemap code may evaluate arguments in an unspecified order, causing it to read an invalid string length when the argument is not a string type. This can lead to program aborts or segmentation faults.

Join the discussion

Criminal IP by AI SPERA introduces AITEM, an AI-powered evolution of Attack Surface Management (ASM) that extends beyond traditional asset discovery. AITEM integrates threat intelligence with AI to connect exposure discovery, investigation, prioritization, and automated response. It aggregates data from external assets, internal infrastructure, open-source intelligence, dark web sources, leaked data, and emerging vulnerabilities to provide a comprehensive threat exposure management approach. The solution aims to help security teams focus on meaningful risks and accelerate response times amid increasing attacker automation. This announcement reflects a broader industry trend toward AI-driven, integrated security operations.

LowNews
Join the discussion

A former core infrastructure engineer at an industrial firm conducted a cyber extortion attack by deleting administrator accounts and resetting hundreds of passwords, effectively locking the company out of its systems. He demanded 20 bitcoin ransom to prevent further damage. The attack was discovered quickly, and the firm did not pay the ransom. Law enforcement traced the attack to the engineer, who pleaded guilty and was sentenced to 32 months in prison.

HighBreach
Join the discussion

Out-of-bounds read in the VarOpt union deserialization of Apache DataSketches C++ (repo: datasketches-cpp). var_opt_union::deserialize() read the 32-byte preamble of a non-empty union after checking that only 8 bytes were available, so a truncated serialized union could cause a read of up to 24 bytes past the end of the input. For such inputs, the size remaining for the embedded sketch was also computed by an unsigned subtraction that could wrap around, so the embedded sketch's own size checks no longer limited reads to the input. The bytes read can become part of the deserialized union's state. This can cause a crash (denial of service) and could expose adjacent memory contents. This issue affects Apache DataSketches C++: from 2.0.0-incubating before 5.3.0. Only applications that deserialize VarOpt unions from untrusted sources are affected. Users are recommended to upgrade to version 5.3.0, which fixes this issue.

Join the discussion

Out-of-bounds read in the compact Theta sketch deserialization of Apache DataSketches C++ (repo: datasketches-cpp). compact_theta_sketch::deserialize() and wrapped_compact_theta_sketch::wrap() read header fields before checking that the input was long enough. For the compressed format, the size check could be defeated by a 32-bit overflow, and two header fields that control decoding were not validated; this also affected deserialization from a stream. A crafted or truncated sketch could cause a read past the end of the input. In the compressed case the over-read can be large, and the bytes read can become part of the deserialized sketch. This can cause a crash (denial of service) and could expose adjacent memory contents. This issue affects Apache DataSketches C++: from 3.1.0 before 5.3.0. Only applications that deserialize Theta sketches from untrusted sources are affected. Users are recommended to upgrade to version 5.3.0, which fixes this issue.

Join the discussion

Out-of-bounds read and write in the CPC sketch deserialization of Apache DataSketches C++ (repo: datasketches-cpp). A crafted serialized CPC sketch passed to cpc_sketch::deserialize(), from either a byte buffer or a stream, can cause the decompressor to read past the end of the compressed data, because the read position was only checked after decoding finished. In the hybrid flavor, it can also cause a write outside an internal heap buffer, because decoded row indices were not validated. Several other header fields and decoded values, including lg_k, were also not validated. This can corrupt heap memory, causing a crash and potentially enabling further exploitation. This issue affects Apache DataSketches C++: from 2.0.0-incubating before 5.3.0. Only applications that deserialize CPC sketches from untrusted sources are affected. Users are recommended to upgrade to version 5.3.0, which fixes this issue.

Join the discussion

Heap buffer overflow in the HLL sketch deserialization of Apache DataSketches C++ (repo: datasketches-cpp). When deserializing a sketch in LIST mode, from either a byte buffer or a stream, the coupon count was read from the input and used as the number of entries to copy into a fixed buffer of 8 entries, without checking it against the buffer's capacity. A crafted sketch could cause a write of up to 988 bytes past the end of this internal heap buffer. This can corrupt heap memory, causing a crash and potentially enabling further exploitation. This issue affects Apache DataSketches C++: from 1.0.0-incubating before 5.3.0. Only applications that deserialize HLL sketches from untrusted sources are affected. Users are recommended to upgrade to version 5.3.0, which fixes this issue.

Join the discussion

CVE-2026-106139 is a medium severity cross-site scripting (XSS) vulnerability in Progress Software Kendo UI for Vue. Versions from 2.5.0 up to but not including 10.1.0 are affected. The issue arises because the default Chart tooltip renders formatted point values as raw HTML without encoding, allowing an attacker with low privileges to inject malicious HTML and JavaScript. Exploitation requires user interaction (hovering over the affected chart data point) and can compromise confidentiality and integrity of application data.

Join the discussion

CVE-2026-106138 is a medium severity vulnerability in Progress Software's KendoReact library affecting versions from 1.1.0 up to but not including 16.2.0. The issue is an improper neutralization of script-related HTML tags (CWE-80) in the default Chart tooltip, which renders formatted point values as raw HTML without encoding. This allows an attacker with low privileges who can influence chart-bound string values to inject HTML with event handlers that execute JavaScript when a user hovers over the affected data point. Exploitation can compromise confidentiality and integrity of accessible data.

Join the discussion

Showing 1 to 10 of 147015 results

Filters:Package: pkg:npm/@progress/kendo-vue-charts
Page 1 of 14702
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses