Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
0 protobufjs-cli is the command line add-on for protobuf.js. Prior to 1.3.2 and 2.5.0, a previous fix for unsafe name handling in pbjs static / static-module code generation was incomplete. Affected versions of protobufjs-cli could still emit unsafe JavaScript references when generating static output from crafted JSON descriptor input. The common case of parsing schemas from .proto files is not affected. This is a bypass of CVE-2026-44295. An attacker who can provide or influence pre-parsed JSON descriptors passed to pbjs static code generation may be able to cause generated JavaScript output to contain attacker-controlled code. The injected code may execute if the generated file is later executed or imported and an affected generated API path is invoked. This vulnerability is fixed in 1.3.2 and 2.5.0. Join the discussion | CVE Database V5 | 06/22/2026, 16:16:05 UTC Added: 06/22/2026, 17:39:39 UTC |
0 CVE-2026-44295 is a high-severity vulnerability in protobufjs-cli, the command line add-on for protobuf.js. Before versions 1.2.1 and 2.0.2, the static code generation feature (pbjs) could produce unsafe JavaScript identifiers derived from schema-controlled names without proper sanitization. This flaw allows crafted schemas or JSON descriptors to inject unsafe code into the generated JavaScript output. The vulnerability is classified as CWE-94 (Improper Control of Generation of Code). It has a CVSS v3. Join the discussion | CVE Database V5 | 05/13/2026, 14:50:39 UTC Added: 05/13/2026, 15:22:09 UTC |
protobufjs-cli is the command line add-on for protobuf.js. Prior to 1.2.1 and 2.0.2, pbts invoked JSDoc by building a shell command string from input file paths and executing it through child_process.exec. File paths containing shell metacharacters could therefore be interpreted by the shell instead of being passed to JSDoc as plain arguments. This vulnerability is fixed in 1.2.1 and 2.0.2. Join the discussion | CVE Database V5 | 05/13/2026, 14:49:30 UTC Added: 05/13/2026, 15:21:55 UTC |
Showing 1 to 3 of 3 results