Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
CVE-2026-18976 is a medium severity vulnerability in NousResearch hermes-agent up to version 0.16.0. It involves incorrect privilege assignment in the get_tool_definitions function within the disabled_toolsets Handler. The vulnerability can be exploited remotely without user interaction. Public exploit details have been disclosed. No official patch or remediation guidance is currently available. Join the discussion | CVE Database V5 | 08/06/2026, 01:45:12 UTC Added: 08/06/2026, 02:11:52 UTC |
CVE-2026-18775 is a server-side request forgery (SSRF) vulnerability in the NousResearch hermes-agent up to version 0.16.0. It affects the browser_snapshot function in the tools/browser_tool.py component. The vulnerability allows remote attackers to manipulate server requests. The vendor has not responded to disclosure attempts, and no official patch or remediation is currently available. The CVSS 4.0 score rates this vulnerability as medium severity. Join the discussion | CVE Database V5 | 08/04/2026, 16:15:09 UTC Added: 08/04/2026, 16:28:46 UTC |
0 A vulnerability was detected in NousResearch hermes-agent up to 2026.5.16. This impacts the function extract_media of the file gateway/platforms/base.py of the component Live Webhook Endpoint. Performing a manipulation results in path traversal. The attack may be initiated remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. Join the discussion | CVE Database V5 | 07/04/2026, 13:00:08 UTC Added: 07/04/2026, 13:22:07 UTC |
A weakness has been identified in NousResearch hermes-agent up to 2026.4.30. The impacted element is the function AIAgent.run_conversation of the file run_agent.py of the component HTTP API. This manipulation of the argument todos causes denial of service. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way. Join the discussion | CVE Database V5 | 07/04/2026, 12:00:07 UTC Added: 07/04/2026, 12:21:53 UTC |
A security flaw has been discovered in NousResearch hermes-agent up to 0.15.2. The affected element is the function shell.exec of the file tui_gateway/server.py. The manipulation results in protection mechanism failure. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way. Join the discussion | CVE Database V5 | 07/04/2026, 11:30:07 UTC Added: 07/04/2026, 11:51:48 UTC |
A vulnerability has been found in NousResearch hermes-agent up to 0.12.0. This affects the function resolve_session_by_title of the file hermes_state.py of the component resume Endpoint. Such manipulation of the argument Title leads to authorization bypass. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. Join the discussion | CVE Database V5 | 06/07/2026, 21:45:09 UTC Added: 06/07/2026, 22:03:35 UTC |
CVE-2026-10223: Injection in NousResearch hermes-agentCVE-2026-10223 0 A weakness has been identified in NousResearch hermes-agent up to 2026.4.30. This affects the function _scan_memory_content of the file tools/memory_tool.py. This manipulation causes injection. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way. Join the discussion | CVE Database V5 | 06/01/2026, 04:15:05 UTC Added: 06/01/2026, 05:33:33 UTC |
CVE-2026-10222: Injection in NousResearch hermes-agentCVE-2026-10222 0 CVE-2026-10222 is a medium severity injection vulnerability in the NousResearch hermes-agent affecting versions 2026.4.0 through 2026.4.30. The flaw exists in the _sanitize_env_lines function within hermes_cli/config.py and can be exploited remotely. Exploitation requires a high level of complexity and is considered difficult. The vendor has not responded to the disclosure, and no official patch or remediation guidance is currently available. Public exploit code has been released. Join the discussion | CVE Database V5 | 06/01/2026, 04:00:11 UTC Added: 06/01/2026, 05:33:33 UTC |
0 A vulnerability was identified in NousResearch hermes-agent up to 0.12.0. Affected by this vulnerability is the function _compress_context of the file run_agent.py. The manipulation leads to injection. It is possible to initiate the attack remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way. Join the discussion | CVE Database V5 | 06/01/2026, 03:45:08 UTC Added: 06/01/2026, 19:52:46 UTC |
A security flaw has been discovered in NousResearch hermes-agent up to 2026.4.16. This vulnerability affects the function _is_blocked_device of the file tools/file_tools.py of the component read_file Tool. Performing a manipulation results in path traversal. The attack may be initiated remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way. Join the discussion | CVE Database V5 | 05/24/2026, 03:15:10 UTC Added: 05/24/2026, 03:31:40 UTC |
Showing 1 to 10 of 10 results