Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
Kedro version 1.2.0 contains a path traversal vulnerability in the _get_versioned_path() method, which unsafely incorporates user-supplied version strings into filesystem paths. This flaw also affects the CLI via the --load-versions parameter, allowing crafted input to escape intended directories. Exploitation can lead to unauthorized file reads and cross-project data access. Join the discussion | CVE Database V5 | 06/12/2026, 15:45:39 UTC Added: 06/12/2026, 17:09:40 UTC |
0 Kedro versions prior to 1.3.0 contain a critical remote code execution vulnerability due to unsafe loading of a logging configuration file specified by the KEDRO_LOGGING_CONFIG environment variable. The logging configuration supports a special key that allows arbitrary callable instantiation, enabling attackers to execute system commands during application startup. This vulnerability is fixed in Kedro version 1.3.0. Join the discussion | CVE Database V5 | 04/06/2026, 17:45:45 UTC Added: 04/06/2026, 18:00:30 UTC |
0 Kedro versions prior to 1.3.0 contain a path traversal vulnerability in the _get_versioned_path() method, which improperly handles user-supplied version strings. This allows an attacker who can control the version string to cause Kedro to load files outside the intended versioned dataset directory. The issue affects multiple entry points including catalog.load, DataCatalog.from_config, and the CLI. This vulnerability can lead to unauthorized file reads, data poisoning, or cross-tenant data access in shared environments. The vulnerability is fixed in Kedro version 1.3. Join the discussion | CVE Database V5 | 04/06/2026, 17:43:21 UTC Added: 04/06/2026, 18:00:30 UTC |
0 A Remote Code Execution (RCE) vulnerability has been identified in the Kedro ShelveStore class (version 0.19.8). This vulnerability allows an attacker to execute arbitrary Python code via deserialization of malicious payloads, potentially leading to a full system compromise. The ShelveStore class uses Python's shelve module to manage session data, which relies on pickle for serialization. Crafting a malicious payload and storing it in the shelve file can lead to RCE when the payload is deserialized. Join the discussion | GCVE Database | 03/20/2025, 12:32:51 UTC Added: 07/06/2026, 23:03:56 UTC |
0 In kedro-org/kedro version 0.19.8, the `pull_package()` API function allows users to download and extract micro packages from the Internet. However, the function `project_wheel_metadata()` within the code path can execute the `setup.py` file inside the tar file, leading to remote code execution (RCE) by running arbitrary commands on the victim's machine. Join the discussion | CVE Database V5 | 03/20/2025, 10:11:39 UTC Added: 10/15/2025, 13:01:24 UTC |
Showing 1 to 5 of 5 results