Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
CVE-2026-68771: Deserialization of Untrusted Data in Comfy-Org ComfyUICVE-2026-68771 0 ComfyUI version 0.23.0 contains a critical deserialization vulnerability in the LoadTrainingDataset node. This flaw allows unauthenticated remote attackers to execute arbitrary Python code by uploading a crafted pickle file via the unauthenticated POST /upload/image endpoint. When the uploaded file is referenced in a workflow graph queued via POST /prompt, the application deserializes the malicious pickle payload using torch.load, leading to code execution as the ComfyUI process user. Join the discussion | CVE Database V5 | 07/31/2026, 21:16:09 UTC Added: 07/31/2026, 21:48:42 UTC |
CVE-2026-52371: n/aCVE-2026-52371 0 CVE-2026-52371 is a Server-Side Request Forgery (SSRF) vulnerability in the xxl-job component, specifically in the jobinfo/trigger interface of version 3.4.0. It allows authenticated attackers to scan internal or external resources by sending crafted HTTP requests. No CVSS score or patch information is currently available. Join the discussion | CVE Database V5 | 07/31/2026, 00:00:00 UTC Added: 07/31/2026, 21:48:42 UTC |
CVE-2026-52232: n/aCVE-2026-52232 0 A reflected cross-site scripting (XSS) vulnerability exists in the /logo.asp component of FS Inc S3150-8T2F Switch version 2.2.0D Build 118101. This vulnerability allows attackers to execute arbitrary JavaScript in the context of a victim's browser via a crafted URL. The affected product is a cloud service. No CVSS score is provided for this vulnerability. Join the discussion | CVE Database V5 | 07/31/2026, 00:00:00 UTC Added: 07/31/2026, 21:48:42 UTC |
CVE-2026-52134: n/aCVE-2026-52134 0 A vulnerability exists in the parseGoosePayload() function of libiec61850 version 1.6 that allows attackers to bypass authentication by using a captured GOOSE frame. This issue could enable unauthorized access or actions within systems using this library. No patch or official remediation guidance is currently available. Join the discussion | CVE Database V5 | 07/31/2026, 00:00:00 UTC Added: 07/31/2026, 21:48:42 UTC |
CVE-2026-51953: n/aCVE-2026-51953 0 A vulnerability in FeehiCMS version 2.1.1 allows an attacker to escalate privileges by exploiting weaknesses in the session management module, authentication logic, and logout handler components. No patch or official remediation guidance is currently available. There is no evidence of exploitation in the wild at this time. Join the discussion | CVE Database V5 | 07/31/2026, 00:00:00 UTC Added: 07/31/2026, 21:48:42 UTC |
Arch Linux disables AUR package adoption to stop malware flood 0 The Arch Linux project has temporarily disabled the adoption of Arch User Repository (AUR) packages due to a recent surge in malicious takeovers of existing packages. This measure aims to prevent further malware distribution through compromised AUR packages. No specific versions of Arch Linux are affected as this is a procedural change in package management rather than a software vulnerability. Join the discussion | Bleeping Computer | 07/31/2026, 21:38:08 UTC Added: 07/31/2026, 21:48:04 UTC |
Malicious code in asdk-plugin-legacy (PyPI) 0 The asdk-plugin-legacy package on PyPI contains malicious code that exfiltrates basic host information such as IP address and username upon installation or import. The package overrides the install command in setup.py to execute this malicious code during installation. It serves no legitimate purpose beyond this data exfiltration. The risk is limited but present due to the unauthorized data collection. Join the discussion | GCVE Database | 07/31/2026, 18:10:08 UTC Added: 07/31/2026, 21:29:28 UTC |
Malicious code in asdk-plugin-ai-platform (PyPI) 0 The asdk-plugin-ai-platform package on PyPI contains malicious code that exfiltrates basic host information such as IP address and username upon installation or import. The package overrides the install command in setup.py to execute this malicious behavior. It serves no legitimate purpose beyond this data exfiltration. Join the discussion | GCVE Database | 07/31/2026, 18:11:51 UTC Added: 07/31/2026, 21:29:28 UTC |
Thumbor has Regex Denial of Service (ReDoS) in `convolution` filter (CVE-2026-53504)CVE-2026-53504 0 Thumbor versions prior to 7.8.0 contain a Regular Expression Denial of Service (ReDoS) vulnerability in the `convolution` filter. The vulnerability arises from a regular expression used to parse the filter parameters, which can cause exponential-time backtracking for certain crafted inputs. This leads to denial of service by exhausting the regex engine and preventing image processing until the regex evaluation completes. Join the discussion | GCVE Database | 07/31/2026, 18:58:28 UTC Added: 07/31/2026, 21:29:20 UTC |
Thumbor proportion filter allows unbounded post-transform resize leading to remote DoS (CVE-2026-53505)CVE-2026-53505 0 Thumbor versions prior to 7.8.0 contain a vulnerability in the 'proportion' filter that allows an attacker to specify an unbounded resize factor. This can cause excessive CPU and memory consumption during image processing, leading to remote denial of service (DoS). The vulnerability arises because the filter does not enforce documented limits on the resize proportion value. Exploitation requires either allowing unsafe URLs or possession of a valid signed URL. A patch is available to enforce bounds on the proportion parameter. Join the discussion | GCVE Database | 07/31/2026, 19:00:44 UTC Added: 07/31/2026, 21:29:20 UTC |
Showing 1 to 10 of 22340 results