Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
0 Improper neutralization of special elements in data query logic in the MongoDB integration for Laravel can cause an array supplied to an explicit equality filter to be interpreted as a query condition rather than as a literal value. This affects the three-argument `where` method when the operator is `=` or `eq`, as well as the `find` and `delete` methods that use that code path. An attacker who can cause an affected application to supply an operator-shaped array to one of these APIs may obtain a document other than the intended target or delete documents beyond the intended target. Join the discussion | CVE Database V5 | 09/10/2026, 17:37:03 UTC Added: 09/10/2026, 17:37:58 UTC |
Tesseract is an open source OCR engine. In version 5.5.3 and earlier, the callback form of GenericVector::read in src/ccutil/genericvector.h reads the independent int32 fields reserved and size_used_ from a .traineddata model without a cap or an invariant check. reserve(reserved) allocates the backing array, but the callback loop writes size_used_ elements. A crafted TESSDATA_INTTEMP component with version_id 4 or later can therefore set reserved to a small value and size_used_ to a large value when fontinfo_table_.read(fp, read_info) is called from src/classify/intproto.cpp, causing a heap out-of-bounds write of FontInfo structures, heap corruption, a crash, or potentially controlled corruption. No fixed release is available as of this review. Join the discussion | CVE Database V5 | 09/10/2026, 17:37:01 UTC Added: 09/10/2026, 17:37:58 UTC |
0 In the silabser.sys driver for CP210x devices v11.5.0 and earlier, a local unprivileged user with a malicious device can use malformed packets to corrupt kernel pool memory, resulting in arbitrary code execution with escalated privileges. Join the discussion | CVE Database V5 | 09/10/2026, 17:15:49 UTC Added: 09/10/2026, 17:37:58 UTC |
0 In the silabser.sys driver for CP210x devices v11.5.0 and earlier, a local unprivileged user with a malicious device can use malformed packets to leak up to 145 bytes of uninitialized kernel pool memory. This vulnerability affects Windows 10 and earlier. Join the discussion | CVE Database V5 | 09/10/2026, 17:15:04 UTC Added: 09/10/2026, 17:37:58 UTC |
In the silabser.sys Windows 8 driver for CP210x devices, a local unprivileged user can use incorrect driver settings to cause a kernel crash. Join the discussion | CVE Database V5 | 09/10/2026, 17:13:56 UTC Added: 09/10/2026, 17:37:58 UTC |
CVE-2026-85228 is an integer overflow vulnerability in the tensor buffer validation component of the Deep Java Library (DJL), an open-source Java framework for deep learning maintained by Amazon. The flaw occurs when a crafted tensor payload declares a shape whose computed byte size exceeds the 32-bit signed integer range, causing the size to wrap and allowing an undersized buffer to pass validation. This leads to out-of-bounds reads during tensor operations. Exploitation could allow a remote, unauthenticated attacker to access adjacent process memory or cause a denial of service. A fix has been released in DJL version 0.37.0. Users are advised to upgrade to this version or later. No workaround other than upgrading is available, but limiting tensor input to trusted sources can reduce risk until patched. Join the discussion | AWS Security Bulletins | 09/10/2026, 17:13:16 UTC Added: 09/10/2026, 17:19:59 UTC |
The provided information discusses a new European regulation requiring manufacturers of routers, cameras, watches, and software to comply with a 24-hour notification rule. This rule mandates rapid reporting of cybersecurity incidents or vulnerabilities. The content is a news article summarizing this regulatory change rather than describing a specific vulnerability or exploit. Join the discussion | Reddit Cybersecurity | 09/10/2026, 16:40:14 UTC Added: 09/10/2026, 16:50:53 UTC |
0 OS command injection in the advanced-rule parser of ConfigServer Security & Firewall allows a remote attacker who controls a configured allow/deny feed to execute arbitrary commands as root, due to insufficient validation of feed-supplied rule data. The vulnerability affects versions of the software originally distributed by ConfigServer, as well as versions of the WebPros-maintained fork that contain the vulnerable code. WebPros has addressed the vulnerability in version 16.30. Other forks or independently maintained versions of ConfigServer Security & Firewall (CSF) may also be affected and should be evaluated independently. Join the discussion | CVE Database V5 | 09/10/2026, 16:24:52 UTC Added: 09/10/2026, 16:37:33 UTC |
Path traversal in Plesk's Backup Manager causes arbitrary file write as root by an authenticated customer. Join the discussion | CVE Database V5 | 09/10/2026, 16:24:52 UTC Added: 09/10/2026, 16:37:33 UTC |
0 Improper escaping of a request URL in ConfigServer Security & Firewall allows an unauthenticated remote attacker to execute arbitrary commands as the CSF service account via shell command injection. The vulnerability affects versions of the software originally distributed by ConfigServer, as well as versions of the WebPros-maintained fork that contain the vulnerable code. WebPros has addressed the vulnerability in version 16.30. Other forks or independently maintained versions of ConfigServer Security & Firewall (CSF) may also be affected and should be evaluated independently. Join the discussion | CVE Database V5 | 09/10/2026, 16:24:52 UTC Added: 09/10/2026, 16:37:33 UTC |
Showing 1 to 10 of 131937 results