Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
A vulnerability was identified in realjerrytang tacomall 1.0.0. Impacted is the function OrgStaffServiceImpl.add of the file ApiMaApplication.java of the component api-admin Backend. The manipulation of the argument isAdmin/jobId leads to improper authorization. Remote exploitation of the attack is possible. The exploit is publicly available and might be used. Join the discussion | CVE Database V5 | 09/29/2026, 05:15:10 UTC Added: 09/29/2026, 05:18:19 UTC |
A flaw has been found in coolbeans1212 MateisHomePage-Website up to ea2a4226deeca27ab1fb9df0552ec76444547811. Affected by this issue is some unknown functionality of the file users.php. This manipulation of the argument Search causes cross site scripting. The attack can be initiated remotely. The exploit has been published and may be used. Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available. Patch name: 6406308df9771d2fd477b56dafe4878dd846df6e. Applying a patch is the recommended action to fix this issue. Join the discussion | CVE Database V5 | 09/29/2026, 05:00:18 UTC Added: 09/29/2026, 05:18:19 UTC |
Multiple vulnerabilities have been identified in Pgpool-II, a software provided by the Pgpool Global Development Group. Specific details about the nature of these vulnerabilities, affected versions, or exploitation methods have not been disclosed. MediumVulnerability Join the discussion | JVN Japan | 09/29/2026, 05:00:00 UTC Added: 09/29/2026, 05:12:02 UTC |
0 CVE-2026-102290 is a cross-site scripting (XSS) vulnerability in CodeCanyon Rocket LMS versions 2.0, 2.1, and 2.2. The flaw exists in the Student Profile Image Upload component and can be exploited remotely by an attacker to execute malicious scripts. The vulnerability has been publicly disclosed, but the vendor has not responded or provided a patch. The CVSS 4.0 base score is 5.1, indicating a medium severity risk. Join the discussion | CVE Database V5 | 09/29/2026, 04:45:14 UTC Added: 09/29/2026, 05:03:30 UTC |
0 CVE-2026-102264 is a cross-site scripting (XSS) vulnerability in the mwasikz robo-cafe-rms product affecting the Edit Profile feature in the frontend/update-account.php file. Manipulating the Name, Address, or City parameters can lead to XSS. The vulnerability allows remote exploitation and public exploit code is available. The product uses a rolling release model, so specific affected versions are not provided. The vendor has not responded to the disclosure. The CVSS 4.0 score rates this as a medium severity issue. Join the discussion | CVE Database V5 | 09/29/2026, 04:30:13 UTC Added: 09/29/2026, 04:48:19 UTC |
0 CVE-2026-102263 is a medium-severity vulnerability in the mwasikz robo-cafe-rms software, specifically involving an unrestricted file upload issue in the manage-food.php file. The vulnerability allows remote attackers to upload files without restriction. The product uses a rolling release model, so no specific affected or fixed versions are identified. The vendor was notified but did not respond, and the exploit has been publicly disclosed. Join the discussion | CVE Database V5 | 09/29/2026, 04:15:10 UTC Added: 09/29/2026, 04:33:25 UTC |
0 CVE-2026-102261 is an authorization bypass vulnerability in owen2345 Camaleon CMS affecting versions 2.9.0, 2.9.1, and 2.9.2. The flaw exists in the Media Crop Handler component, specifically in the crop function of app/controllers/camaleon_cms/admin/media_controller.rb. The vulnerability allows remote attackers to bypass authorization by manipulating the saved_avatar argument. An exploit has been published. Upgrading to version 2.9.3 addresses this issue. Join the discussion | CVE Database V5 | 09/29/2026, 04:00:13 UTC Added: 09/29/2026, 04:33:25 UTC |
0 shell-quote's `quote()` function emits a `{ comment }` token as `#` followed by its text, which comments out the rest of the shell line, including the opening quote of any later string token. A line terminator (\n, \r, U+2028, U+2029) in that later string therefore ends the comment, and the rest of the string is parsed as shell input: `quote(['echo', 'ok', { comment: 'x' }, 'a\nid;#'])` runs `id` in sh, bash, dash, ksh and zsh. `parse()` emits a comment token for a `#` in the middle of a word (for example `http://example.com/#frag`), so callers that combine `parse()` output with another untrusted string, such as `quote(parse(untrustedCommand).concat(untrustedArg))`, are affected. The fix for CVE-2026-9277 rejected line terminators in the comment's own text, but not in the tokens after it. Fixed in 1.11.0: `quote()` throws a `TypeError` when a string after a `{ comment }` token contains a line terminator. Join the discussion | CVE Database V5 | 09/29/2026, 03:47:36 UTC Added: 09/29/2026, 04:03:31 UTC |
0 A security flaw has been discovered in REBUILD up to 4.4.11. This vulnerability affects unknown code of the file /commons/file-editor-save. The manipulation of the argument url/fileKey results in missing authorization. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way. Join the discussion | CVE Database V5 | 09/29/2026, 03:45:12 UTC Added: 09/29/2026, 04:03:31 UTC |
0 Flatpak's process ID namespace separation does not prevent a sandboxed app's kill(0, signal) or killpg(0, signal) calls from reaching processes outside the sandbox that share the same process group. A malicious or compromised Flatpak app can use this to cause denial of service by terminating processes outside its sandbox, such as the desktop shell. Join the discussion | CVE Database V5 | 09/29/2026, 03:43:16 UTC Added: 09/29/2026, 04:03:31 UTC |
Showing 1 to 10 of 140227 results