Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

CVE-2026-42169: Incorrect Calculation of Buffer Size in Red Hat Red Hat Enterprise Linux 6CVE-2026-42169
0

CVE-2026-42169 is a heap-buffer-overflow vulnerability in GIMP's APNG file loader and DDS plug-in affecting Red Hat Enterprise Linux 6. The flaw occurs when the fcTL width exceeds the IHDR width in APNG files, causing pixel data to overflow heap allocations. A similar heap overflow exists in the DDS plug-in due to a bits-per-pixel mismatch. Exploitation requires a user to open a specially crafted image file, potentially leading to code execution. No official fix or mitigation meeting Red Hat's criteria is currently available.

Join the discussion
CVE-2026-18723: Improper Authorization in diaowen DWSurveyCVE-2026-18723
0

A vulnerability was determined in diaowen DWSurvey up to 6.14.0. The affected element is an unknown function of the file /api/dwsurvey/app/survey/up-survey-status.do of the component Survey Status Handler. This manipulation causes improper authorization. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.

Join the discussion
CVE-2026-18722: Authorization Bypass in diaowen DWSurveyCVE-2026-18722
0

CVE-2026-18722 is an authorization bypass vulnerability in diaowen DWSurvey versions 6.0 through 6.14.0. It affects the devSurvey function in the DwDeisgnSurveyController component, allowing remote attackers to bypass authorization controls. The vulnerability has a medium severity rating with a CVSS score of 5.3. No official patch or remediation has been announced by the vendor, who has not responded to disclosure attempts. Exploit details have been made public, but there are no confirmed reports of exploitation in the wild.

Join the discussion
CVE-2026-18721: Open Redirect in kalcaddle kodboxCVE-2026-18721
0

An open redirect vulnerability exists in kalcaddle kodbox 1.67 Build 02 within the SSO API Login component. The issue arises from improper handling of the callbackUrl parameter in the /user/sso/apiLogin endpoint, allowing attackers to redirect users to arbitrary external sites. This vulnerability can be exploited remotely and requires user interaction. The vendor has not responded to the disclosure, and no official fix or patch has been announced. The CVSS 4.0 base score is 5.3, indicating a medium severity level.

Join the discussion
CVE-2026-14818: CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in Zyxel ATP series firmwareCVE-2026-14818
0

CVE-2026-14818 is a path traversal vulnerability in Zyxel ATP series and related firmware versions that allows an authenticated administrator to execute crafted malicious configuration files via a CLI command. The affected firmware versions include Zyxel ATP series from V4.32 through V5.42 Patch 1, USG FLEX series from V4.50 through V5.42 Patch 1, USG FLEX 50(W) series from V4.16 through V5.42 Patch 1, and USG20(W)-VPN series from V4.16 through V5.42 Patch 1. This vulnerability can lead to high impact on confidentiality, integrity, and availability. No official patch or remediation guidance is currently provided by the vendor.

Join the discussion
ISC Stormcast For Tuesday, August 4th, 2026 https://isc.sans.edu/podcastdetail/10036, (Tue, Aug 4th)
0

The provided information references an ISC Stormcast podcast episode dated August 4th, 2026, from the SANS Internet Storm Center. No specific vulnerability details, technical descriptions, or affected software versions are provided in the source content. The entry does not describe any concrete security threat or exploit.

MediumVulnerability
Join the discussion
New York Awards $9 Million to Strengthen Cybersecurity at 153 Water Systems
0

New York State has awarded over $9 million in grants to 153 drinking water and wastewater systems to enhance their cybersecurity defenses. This initiative follows a recent multistate cyber campaign targeting water infrastructure, which caused operational disruptions in several states but did not affect New York utilities publicly. The funding supports cybersecurity assessments, upgrades, and compliance with new state cybersecurity standards for utilities. The campaign involved attacks on operational technology systems, including programmable logic controllers, and is suspected to be linked to Iranian threat actors. Federal agencies recommend removing exposed OT devices from the internet and securing remote access. The grants aim to improve resilience and compliance with mandatory cybersecurity measures for critical water infrastructure.

MediumVulnerability#local
Join the discussion
CVE-2026-18719: SQL Injection in cemtan sar2htmlCVE-2026-18719
0

CVE-2026-18719 is a medium severity SQL injection vulnerability in cemtan sar2html version 4.0.0. The issue exists in the sar2html.py file within the Search component, where manipulation of the Search argument can lead to SQL injection. The vulnerability can be exploited remotely without user interaction. The vendor has not responded to the disclosure, and no official patch or remediation is currently available. Exploit code is publicly available, but no known widespread exploitation has been reported.

Join the discussion
CVE-2026-58045: CWE-400 Uncontrolled Resource Consumption in nodejs nodeCVE-2026-58045
0

A vulnerability in Node.js allows a specially crafted TypedArray with a spoofed byteLength to trigger an assertion failure in synchronous node:zlib APIs, causing the process to crash. This affects all 11 synchronous zlib functions and can be exploited repeatedly to cause denial of service. The issue impacts specific versions of Node.js 22.x, 24.x, and 26.x.

Join the discussion
CVE-2026-58044: CWE-444 HTTP Request Smuggling in nodejs nodeCVE-2026-58044
0

A vulnerability in the Node.js HTTP client can cause HTTP request desynchronization in forwarding proxies that rebuild outbound headers from visible IncomingMessage headers while reusing backend connections. This occurs because Node.js may omit headers beyond configured header count limits from user-accessible header collections but still use them internally for HTTP framing, potentially hiding headers like Content-Length. This affects Node.js versions 22.23.1, 24.18.0, and 26.5.0.

Join the discussion

Showing 1 to 10 of 21985 results

Filters:Package: pkg:npm/@serverless-devs/s
Page 1 of 2199
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses