Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
This entry is a daily security news update from the SANS Internet Storm Center (ISC) titled 'ISC Stormcast For Friday, September 18th, 2026.' It does not contain any specific information about a security threat, vulnerability, or exploit. LowNews Join the discussion | SANS ISC Handlers Diary | 09/18/2026, 02:00:02 UTC Added: 09/18/2026, 02:01:40 UTC |
0 CVE-2026-93331 is a medium severity vulnerability in GPAC version 26.08-DEV affecting the RTP Depacketizer component. It involves an out-of-bounds read in the function gf_rtp_parse_ttxt due to improper handling of the argument size. The vulnerability can be exploited remotely without authentication. Upgrading to version abi-16.26 resolves the issue. Join the discussion | CVE Database V5 | 09/18/2026, 01:45:14 UTC Added: 09/18/2026, 02:02:11 UTC |
CVE-2026-93312 is a medium severity vulnerability in Freedesktop Poppler version 26.07.0. It involves a null pointer dereference in the JBIG2Stream::rewind function within the poppler/JBIG2Stream.cc file. This flaw can be triggered remotely and requires user interaction. An exploit has been published. Upgrading to Poppler version 26.08.0 addresses this issue. Join the discussion | CVE Database V5 | 09/18/2026, 00:45:12 UTC Added: 09/18/2026, 01:32:05 UTC |
0 CVE-2026-93311 is an integer overflow vulnerability in Freedesktop Poppler version 26.07.0. It affects the SampledFunction::SampledFunction function in the poppler/Function.cc file, where manipulation of the BitsPerSample argument can cause an integer overflow. The vulnerability can be exploited remotely and public exploit code is available. The project has been informed but has not yet responded or released a fix. Join the discussion | CVE Database V5 | 09/18/2026, 00:30:07 UTC Added: 09/18/2026, 01:32:05 UTC |
0 NASA CryptoLib version 1.5.0 has an authentication downgrade vulnerability in its Telecommand receive path. The vulnerability arises because the receiver selects the Security Association (SA) based only on the SPI field in the incoming frame without verifying that the SA is authorized for the frame's GVCID. This flaw can allow unauthorized use of critical functions due to missing authentication checks. Join the discussion | CVE Database V5 | 09/18/2026, 00:26:28 UTC Added: 09/18/2026, 01:32:05 UTC |
0 A vulnerability was identified in O-RAN-SC SMO OAM 2025-06-10. This affects an unknown part of the component VES Collector. The manipulation leads to allocation of resources. Remote exploitation of the attack is possible. The exploit is publicly available and might be used. The project was informed of the problem early through a bug report but has not responded yet. Join the discussion | CVE Database V5 | 09/18/2026, 00:00:12 UTC Added: 09/18/2026, 00:32:11 UTC |
0 A vulnerability was determined in O-RAN-SC SMO OAM 2025-06-10. Affected by this issue is some unknown functionality of the component VES Collector. Executing a manipulation can lead to allocation of resources. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through a bug report but has not responded yet. Join the discussion | CVE Database V5 | 09/17/2026, 23:30:12 UTC Added: 09/17/2026, 23:32:21 UTC |
The Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.6.9 via the set_customer_object due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to enumerate arbitrary customer records and disclose personally identifiable information - including first name, last name, email address, and phone number - by iterating the customer[id] parameter. This issue is exploitable only when the site is configured with customer authentication disabled (guest checkout enabled). Join the discussion | CVE Database V5 | 09/17/2026, 23:27:10 UTC Added: 09/17/2026, 23:32:21 UTC |
The Brizy – Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘rootAttributes’ parameter in all versions up to, and including, 2.8.14 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Join the discussion | CVE Database V5 | 09/17/2026, 23:27:10 UTC Added: 09/17/2026, 23:32:21 UTC |
0 Aureus ERP through 1.6.0 stores the Payment Term note field unsanitized and renders it as raw HTML in the Accounting plugin. Authenticated users with payment-term create permission can submit arbitrary JavaScript to the payment-terms endpoint, which persists to the database and executes in browsers of all users viewing that Payment Term record. Join the discussion | CVE Database V5 | 09/17/2026, 23:25:13 UTC Added: 09/17/2026, 23:32:21 UTC |
Showing 1 to 10 of 135460 results