Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

CVE-2026-68771: Deserialization of Untrusted Data in Comfy-Org ComfyUICVE-2026-68771
0

ComfyUI version 0.23.0 contains a critical deserialization vulnerability in the LoadTrainingDataset node. This flaw allows unauthenticated remote attackers to execute arbitrary Python code by uploading a crafted pickle file via the unauthenticated POST /upload/image endpoint. When the uploaded file is referenced in a workflow graph queued via POST /prompt, the application deserializes the malicious pickle payload using torch.load, leading to code execution as the ComfyUI process user.

Join the discussion
CVE-2026-52371: n/aCVE-2026-52371
0

CVE-2026-52371 is a Server-Side Request Forgery (SSRF) vulnerability in the xxl-job component, specifically in the jobinfo/trigger interface of version 3.4.0. It allows authenticated attackers to scan internal or external resources by sending crafted HTTP requests. No CVSS score or patch information is currently available.

Join the discussion
CVE-2026-52232: n/aCVE-2026-52232
0

A reflected cross-site scripting (XSS) vulnerability exists in the /logo.asp component of FS Inc S3150-8T2F Switch version 2.2.0D Build 118101. This vulnerability allows attackers to execute arbitrary JavaScript in the context of a victim's browser via a crafted URL. The affected product is a cloud service. No CVSS score is provided for this vulnerability.

Join the discussion
CVE-2026-52134: n/aCVE-2026-52134
0

A vulnerability exists in the parseGoosePayload() function of libiec61850 version 1.6 that allows attackers to bypass authentication by using a captured GOOSE frame. This issue could enable unauthorized access or actions within systems using this library. No patch or official remediation guidance is currently available.

Join the discussion
CVE-2026-51953: n/aCVE-2026-51953
0

A vulnerability in FeehiCMS version 2.1.1 allows an attacker to escalate privileges by exploiting weaknesses in the session management module, authentication logic, and logout handler components. No patch or official remediation guidance is currently available. There is no evidence of exploitation in the wild at this time.

Join the discussion
Arch Linux disables AUR package adoption to stop malware flood
0

The Arch Linux project has temporarily disabled the adoption of Arch User Repository (AUR) packages due to a recent surge in malicious takeovers of existing packages. This measure aims to prevent further malware distribution through compromised AUR packages. No specific versions of Arch Linux are affected as this is a procedural change in package management rather than a software vulnerability.

Join the discussion
Malicious code in asdk-plugin-legacy (PyPI)
0

The asdk-plugin-legacy package on PyPI contains malicious code that exfiltrates basic host information such as IP address and username upon installation or import. The package overrides the install command in setup.py to execute this malicious code during installation. It serves no legitimate purpose beyond this data exfiltration. The risk is limited but present due to the unauthorized data collection.

Join the discussion
Malicious code in asdk-plugin-ai-platform (PyPI)
0

The asdk-plugin-ai-platform package on PyPI contains malicious code that exfiltrates basic host information such as IP address and username upon installation or import. The package overrides the install command in setup.py to execute this malicious behavior. It serves no legitimate purpose beyond this data exfiltration.

Join the discussion
Thumbor has Regex Denial of Service (ReDoS) in `convolution` filter (CVE-2026-53504)CVE-2026-53504
0

Thumbor versions prior to 7.8.0 contain a Regular Expression Denial of Service (ReDoS) vulnerability in the `convolution` filter. The vulnerability arises from a regular expression used to parse the filter parameters, which can cause exponential-time backtracking for certain crafted inputs. This leads to denial of service by exhausting the regex engine and preventing image processing until the regex evaluation completes.

Join the discussion
Thumbor proportion filter allows unbounded post-transform resize leading to remote DoS (CVE-2026-53505)CVE-2026-53505
0

Thumbor versions prior to 7.8.0 contain a vulnerability in the 'proportion' filter that allows an attacker to specify an unbounded resize factor. This can cause excessive CPU and memory consumption during image processing, leading to remote denial of service (DoS). The vulnerability arises because the filter does not enforce documented limits on the resize proportion value. Exploitation requires either allowing unsafe URLs or possession of a valid signed URL. A patch is available to enforce bounds on the proportion parameter.

Join the discussion

Showing 1 to 10 of 22336 results

Filters:Package: pkg:npm/@tinacms/cli
Page 1 of 2234
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses