Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
If `shutil.unpack_archive()` is given a ZIP archive with an absolute Windows path containing a drive (`C:\\...`) then the archive will be extracted outside the target directory which is different than other operating systems. Only Windows is affected by this vulnerability. Join the discussion | CVE Database V5 | 08/19/2026, 11:42:48 UTC Added: 04/27/2026, 21:15:19 UTC |
0 Python is an interpreted, interactive, object-oriented programming language, which includes modules, classes, exceptions, very high level dynamic data types and dynamic typing. Python supports interfaces to many system calls and libraries, as well as to various windowing systems. Security Fix(es): * python: Python: CPU Denial of Service in HTML parser via repeated unterminated markup declarations (CVE-2026-15308) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Join the discussion | GCVE Database | 08/04/2026, 13:10:10 UTC Added: 07/10/2026, 09:23:58 UTC |
The method "sock_recvfrom_into()" of "asyncio.ProacterEventLoop" (Windows only) was missing a boundary check for the data buffer when using nbytes parameter. This allowed for an out-of-bounds buffer write if data was larger than the buffer size. Non-Windows platforms are not affected. Join the discussion | CVE Database V5 | 07/06/2026, 15:27:55 UTC Added: 04/21/2026, 15:01:07 UTC |
http.cookies.Morsel.js_output() returns an inline <script> snippet and only escapes " for JavaScript string context. It does not neutralize the HTML parser-sensitive sequence </script> inside the generated script element. Mitigation base64-encodes the cookie value to disallow escaping using cookie value. Join the discussion | GCVE Database | 06/30/2026, 23:20:52 UTC Added: 06/12/2026, 11:14:24 UTC |
0 bz2.BZ2Decompressor objects could be reused after a decompression error. If an application caught the resulting OSError and retried with the same decompressor, crafted input could cause the decompressor to resume from an invalid internal state and perform out-of-bounds writes to a stack buffer. This could crash the process when processing untrusted data. Join the discussion | CVE Database V5 | 06/25/2026, 07:40:50 UTC Added: 06/08/2026, 22:48:36 UTC |
tarfile.data_filter could be bypassed using crafted link entries, including symlinks with empty or directory-like names, to redirect later archive members outside the intended extraction directory. This allowed a malicious tar archive to cause tarfile.extractall() to write files outside the destination directory, subject to the permissions of the extracting process. Join the discussion | CVE Database V5 | 06/08/2026, 08:13:38 UTC Added: 06/04/2026, 15:49:02 UTC |
unicodedata.normalize() can take excessive CPU time when processing specially crafted Unicode input containing long runs of combining characters with alternating Canonical Combining Class values. This affects all normalization forms. Join the discussion | CVE Database V5 | 06/05/2026, 13:04:10 UTC Added: 06/03/2026, 15:48:54 UTC |
`xml.parsers.expat` and `xml.etree.ElementTree` use insufficient entropy for Expat hash-flooding protection, which allows a crafted XML document to trigger hash flooding.\r\n\r\nFully mitigating this vulnerability requires both updating libexpat to 2.8.0 or later and applying this patch. Join the discussion | CVE Database V5 | 05/11/2026, 17:19:09 UTC Added: 05/11/2026, 18:06:31 UTC |
This update includes the following RPMs: python3.13: * python3.13-3.13.13-1.1.hum1 (aarch64, x86_64) * python3.13-debug-3.13.13-1.1.hum1 (aarch64, x86_64) * python3.13-devel-3.13.13-1.1.hum1 (aarch64, x86_64) * python3.13-freethreading-3.13.13-1.1.hum1 (aarch64, x86_64) * python3.13-freethreading-debug-3.13.13-1.1.hum1 (aarch64, x86_64) * python3.13-idle-3.13.13-1.1.hum1 (aarch64, x86_64) * python3.13-libs-3.13.13-1.1.hum1 (aarch64, x86_64) * python3.13-test-3.13.13-1.1.hum1 (aarch64, x86_64) * python3.13-tkinter-3.13.13-1.1.hum1 (aarch64, x86_64) * python3.13-3.13.13-1.1.hum1.src (src) Security Fix(es): python3.13: * CVE-2026-1502 * CVE-2026-4786 * CVE-2026-6100 Join the discussion | GCVE Database | 04/23/2026, 11:30:45 UTC Added: 05/27/2026, 21:15:27 UTC |
0 http.cookies.Morsel.js_output() returns an inline <script> snippet and only escapes " for JavaScript string context. It does not neutralize the HTML parser-sensitive sequence </script> inside the generated script element. Mitigation base64-encodes the cookie value to disallow escaping using cookie value. Join the discussion | CVE Database V5 | 04/22/2026, 19:28:08 UTC Added: 04/22/2026, 20:01:07 UTC |
Showing 1 to 10 of 36 results