Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to versions 7.0.16 and 8.0.5, a crafted rule using mixed-case frame syntax could trigger a heap buffer overflow while Suricata is loading signatures. The issue is reached during rule parsing/loading rather than by network traffic alone. Versions 7.0.16 and 8.0.5 contain a fix. As a workaround, preprocess rules to check that frames are all lowercase and/or only load trusted rulesets. Join the discussion | CVE Database V5 | 09/10/2026, 21:02:48 UTC Added: 09/10/2026, 21:17:29 UTC |
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to versions 7.0.16 and 8.0.5, Suricata could repeatedly perform expensive parsing of large HTTP `Content-Disposition` headers during HTTP response body processing. Crafted HTTP traffic could cause excessive CPU usage and denial of service. Versions 7.0.16 and 8.0.5 contain a fix. As a workaround, use a rule like `alert http1 any any -> any any (sid: 1; http.request_header; content: "Content-Disposition:"; startswith; bsize: > 8192; bypass;)`. Join the discussion | CVE Database V5 | 09/10/2026, 21:01:19 UTC Added: 09/10/2026, 21:17:29 UTC |
A potential improper permissions vulnerability was reported in the Lenovo Filez Client application that could allow a local authenticated user to escalate privileges. Join the discussion | CVE Database V5 | 09/10/2026, 21:00:31 UTC Added: 09/10/2026, 21:17:29 UTC |
0 A potential improper authorization vulnerability was reported in the Lenovo File Manager Android Application, distributed exclusively in the Chinese market, that could allow a local authenticated user to read or modify protected files within the application. Join the discussion | CVE Database V5 | 09/10/2026, 21:00:25 UTC Added: 09/10/2026, 21:17:29 UTC |
A potential command injection vulnerability was reported in the Tianxi AI Agent PC Application, distributed exclusively in the Chinese market, that could allow operating system commands to be executed if a local user opens a specially crafted link that is handled by the application. Join the discussion | CVE Database V5 | 09/10/2026, 21:00:19 UTC Added: 09/10/2026, 21:17:29 UTC |
An authentication bypass vulnerability was discovered in Lenovo Software Fix that could allow a local authenticated user to perform arbitrary code execution with elevated privileges. Join the discussion | CVE Database V5 | 09/10/2026, 21:00:13 UTC Added: 09/10/2026, 21:17:29 UTC |
A vulnerability was reported in Lenovo Health Android Application, distributed exclusively in the Chinese market, that could allow an attacker to access sensitive health-related information. Join the discussion | CVE Database V5 | 09/10/2026, 21:00:05 UTC Added: 09/10/2026, 21:17:29 UTC |
IBM Langflow OSS 1.0.0 through 1.11.5 Langflow could allow an unauthenticated attacker to execute arbitrary code and access or modify chat sessions through publicly shared MCP project endpoints due to improper enforcement of public-flow security restrictions and session isolation controls. Join the discussion | CVE Database V5 | 09/10/2026, 20:58:37 UTC Added: 09/10/2026, 21:17:29 UTC |
0 IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to server-side request forgery (SSRF) that could allow a remote, unauthenticated attacker to cause the server to send outbound requests to arbitrary endpoints. Join the discussion | CVE Database V5 | 09/10/2026, 20:57:22 UTC Added: 09/10/2026, 21:17:29 UTC |
0 IBM WebSphere Application Server versions 8.5 and 9.0 contain a vulnerability related to improper authentication controls that could allow a local attacker to escalate privileges and gain unauthorized access to protected resources. This issue is categorized as CWE-94, indicating improper control of code generation, commonly known as code injection. The vulnerability has a CVSS v3.1 score of 6.7, reflecting a medium severity level. No public exploits are known, and no patch or remediation details are provided in the available data. Join the discussion | CVE Database V5 | 09/10/2026, 20:45:57 UTC Added: 09/10/2026, 21:02:40 UTC |
Showing 1 to 10 of 129393 results