Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
0 A vulnerability in Red Hat JBoss Enterprise Application Platform 7.4 prior to 7.4.25 allows unauthenticated attackers to perform bind operations on the IIOP NameService listener without authentication. This flaw enables hijacking of JNDI lookups by binding them to a malicious ORB, potentially leading to man-in-the-middle (MITM) attacks or denial of service (DoS) on subsequent invocations. Join the discussion | GCVE Database | 08/11/2026, 08:49:54 UTC Added: 08/12/2026, 16:12:34 UTC |
0 CVE-2026-15562 is an integer overflow vulnerability in the MessageReader component of jboss-remoting within Red Hat JBoss Enterprise Application Platform 7.4 prior to version 7.4.25. A remote unauthenticated attacker who can reach certain exposed ports and complete a jboss-remoting handshake can trigger out-of-memory (OOM) errors that degrade server performance and cause denial of service. The vulnerability has a CVSS v3.1 base score of 7.5 (high severity) and does not impact confidentiality or integrity but severely impacts availability. Join the discussion | GCVE Database | 08/11/2026, 08:49:50 UTC Added: 08/12/2026, 16:12:34 UTC |
0 CVE-2026-15561 is a vulnerability in Red Hat JBoss Enterprise Application Platform 7.4 prior to version 7.4.25. It involves the undertow HTTP/1.1 chunked-transfer decoder lacking limits on size and count, allowing an unauthenticated attacker to cause the JVM to run out of memory. This results in a denial of service by stopping all deployments on the listener. The vulnerability has a CVSS score of 7.5 (high severity) and does not affect confidentiality or integrity but impacts availability. Join the discussion | GCVE Database | 08/11/2026, 08:49:49 UTC Added: 08/12/2026, 16:12:34 UTC |
0 CVE-2026-15556 is a high-severity vulnerability in Red Hat JBoss Enterprise Application Platform versions prior to 7.4.25. It involves improper verification of cryptographic signatures in Picketlink's SAML Service Provider signature validation. An attacker can exploit this flaw by crafting a SAML response with zero assertion elements matching the signature check, allowing authentication as any principal with any roles on the protected application. Red Hat JBoss EAP 8.x is not affected as it does not include the vulnerable Picketlink components. A security update fixing this issue is available in version 7.4.25. Join the discussion | GCVE Database | 08/11/2026, 08:49:44 UTC Added: 08/12/2026, 16:12:34 UTC |
0 CVE-2026-15555 is a high-severity vulnerability in Red Hat JBoss Enterprise Application Platform 7.4.25 and earlier versions. It involves insecure deserialization in the Infinispan session replication path, where replicated session data is deserialized without class filtering using the JBoss Marshalling River unmarshaller. This flaw enables remote code execution (RCE) via deserialization gadget chains on every cluster node. A security update fixing this issue is available in version 7.4.25. Join the discussion | GCVE Database | 08/11/2026, 08:49:40 UTC Added: 08/12/2026, 16:12:34 UTC |
0 Red Hat JBoss Enterprise Application Platform 8 is a platform for Java applications based on the WildFly application runtime. This release of Red Hat JBoss Enterprise Application Platform 8.1.7 serves as a replacement for Red Hat JBoss Enterprise Application Platform 8.1.6, and includes bug fixes and enhancements. See the Red Hat JBoss Enterprise Application Platform 8.1.7 Release Notes for information about the most significant bug fixes and enhancements included in this release. Security Fix(es): * io.undertow.jastow-jastow: Jastow Cross-Site Scripting attack due to unsanitized URI (CVE-2025-12799) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Join the discussion | GCVE Database | 07/07/2026, 18:00:04 UTC Added: 07/30/2026, 05:46:52 UTC |
A flaw was found in Undertow. When Undertow receives an HTTP request where the first header line starts with one or more spaces, it incorrectly processes the request by stripping these leading spaces. This behavior, which violates HTTP standards, can be exploited by a remote attacker to perform request smuggling. Request smuggling allows an attacker to bypass security mechanisms, access restricted information, or manipulate web caches, potentially leading to unauthorized actions or data exposure. Join the discussion | CVE Database V5 | 03/27/2026, 16:13:05 UTC Added: 03/27/2026, 18:04:01 UTC |
A flaw was found in Undertow. A remote attacker can exploit this vulnerability by sending `\r\r\r` as a header block terminator. This can be used for request smuggling with certain proxy servers, such as older versions of Apache Traffic Server and Google Cloud Classic Application Load Balancer, potentially leading to unauthorized access or manipulation of web requests. Join the discussion | CVE Database V5 | 03/27/2026, 16:13:05 UTC Added: 03/27/2026, 18:04:01 UTC |
A flaw was found in Undertow. This vulnerability allows a remote attacker to construct specially crafted requests where header names are parsed differently by Undertow compared to upstream proxies. This discrepancy in header interpretation can be exploited to launch request smuggling attacks, potentially bypassing security controls and accessing unauthorized resources. Join the discussion | CVE Database V5 | 03/27/2026, 16:13:03 UTC Added: 03/27/2026, 18:04:01 UTC |
0 Red Hat JBoss Enterprise Application Platform 8 is a platform for Java applications based on the WildFly application runtime. This release of Red Hat JBoss Enterprise Application Platform 8.1.2 serves as a replacement for Red Hat JBoss Enterprise Application Platform 8.1.1, and includes bug fixes and enhancements. See the Red Hat JBoss Enterprise Application Platform 8.1.2 Release Notes for information about the most significant bug fixes and enhancements included in this release. Security Fix(es): * org.eclipse.jgit: XXE vulnerability in Eclipse JGit [eap-8.1.z] (CVE-2025-4949) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Join the discussion | GCVE Database | 11/26/2025, 16:59:20 UTC Added: 06/10/2026, 11:41:47 UTC |
Showing 1 to 10 of 17 results