Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
0 Prefect version 3.6.18 contains a command injection vulnerability in the GitHubRepository block of the prefect-github integration. The vulnerability arises because the reference field is directly concatenated into a git clone command without proper sanitization, allowing injection of arbitrary git command-line options. This can lead to Server-Side Request Forgery (SSRF), credential theft, or remote code execution. The issue affects the aget_directory() and get_directory() methods. GitLab and BitBucket integrations are not affected as they use safer command construction methods. Join the discussion | CVE Database V5 | 05/24/2026, 03:32:32 UTC Added: 05/24/2026, 05:01:37 UTC |
0 CVE-2026-7725 is a medium severity vulnerability in PrefectHQ's prefect up to version 3.6.25.dev6. It involves argument injection through manipulation of the commit_sha or directories arguments in the GitRepository Pull Handler component. The vulnerability can be exploited remotely without user interaction. A fixed version, 3.6.25.dev7, has been released by the vendor to address this issue. Join the discussion | CVE Database V5 | 05/04/2026, 03:00:17 UTC Added: 05/04/2026, 04:22:16 UTC |
A vulnerability has been found in PrefectHQ prefect up to 3.6.28.dev1. Affected by this vulnerability is the function validate_restricted_url of the component Webhook/Notification. The manipulation leads to time-of-check time-of-use. It is possible to initiate the attack remotely. The attack is considered to have high complexity. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. Upgrading to version 3.6.28.dev2 addresses this issue. The identifier of the patch is 7c70ac54a5e101431d83b9f2681ec88d5e0021ed. Upgrading the affected component is advised. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product. Join the discussion | CVE Database V5 | 05/04/2026, 02:45:12 UTC Added: 05/04/2026, 03:06:51 UTC |
A flaw has been found in PrefectHQ prefect up to 3.6.13. Affected is an unknown function of the file /api/events/in of the component WebSocket Endpoint. Executing a manipulation can lead to missing authentication. The attack may be performed from remote. The exploit has been published and may be used. Upgrading to version 3.6.14 is able to address this issue. This patch is called f8afecadf88ea5f73694dafa3a365b9d8fae1ad6. It is recommended to upgrade the affected component. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product. Join the discussion | CVE Database V5 | 05/04/2026, 02:30:18 UTC Added: 05/04/2026, 03:06:51 UTC |
A vulnerability was detected in PrefectHQ prefect up to 3.6.21. This impacts the function endswith of the file /api/health of the component Health Check API. Performing a manipulation results in improper authentication. The attack is possible to be carried out remotely. The exploit is now public and may be used. Upgrading to version 3.6.22 will fix this issue. The patch is named e21617125335025b4b27e7d6f0ca028e8e8f3b79. Upgrading the affected component is recommended. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product. Join the discussion | CVE Database V5 | 05/04/2026, 02:15:18 UTC Added: 05/04/2026, 03:06:51 UTC |
Showing 1 to 5 of 5 results