Skip to main content

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Search: 4443

Search Results: "4443"

Click on any threat for detailed analysis and mitigation recommendations

0

Multiple security vulnerabilities affecting Chromium have been addressed in a series of updates culminating in version 146.0.7680.177. These include use-after-free, heap buffer overflows, integer overflows, out-of-bounds reads and writes, insufficient policy enforcement, and incorrect security UI implementations across various components such as CSS, GPU, WebGL, V8, WebCodecs, Dawn, PDF, WebAudio, WebRTC, and others. The vulnerabilities are critical in nature and have been fixed in these Chromium releases.

Join the discussion

A code injection vulnerability exists in the Bisection component of Google Chrome versions prior to 152.0.7977.65. This flaw allows a remote attacker to obtain sensitive information by leveraging a crafted file. The vulnerability has a medium severity rating and does not affect availability or integrity, only confidentiality.

Join the discussion

--- _-= Per source details. Do not edit below this line.=-_ ## Source: amazon-inspector (713bf7fce40e177608dd5145e1662b4efd3da6c1597d9a1aeb15d7715b865205) The npm postinstall hook runs ensurePlatformBinary(), which downloads a.tgz archive from the hardcoded bare-IP URL https://218.90.133.98:4443/onecode_tgz/onecode-<ver>/onecode-linux-x64-<ver>.tgz, extracts it via `tar -xzf`, chmods the extracted file to 0o755, hardlinks it into bin/.onecode, and the shipped CLI launcher invokes it. The HTTPS request explicitly sets `rejectUnauthorized: false`, disabling TLS certificate verification, and no hash or signature check is performed on the downloaded artifact. The download destination is a bare IPv4 address on a non-standard port, not a publisher-owned domain or a recognized release host. The package name and launcher (@onescience/onecode) mirror the unrelated 'opencode' project — env-var fallbacks reference OPENCODE_BIN_PATH and bundled asset directories are named.opencode/session-seed and.opencode/oneskills — while the executable payload is retrieved from an unrelated hardcoded IP endpoint. Anyone controlling that host, or any on-path network attacker (TLS is disabled), can deliver arbitrary code that executes on every installer's machine.

Join the discussion
0

Heap buffer overflow in WebAudio in Google Chrome prior to 146.0.7680.153 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

Join the discussion

The NuGet package Celigo.Suite.Talk version 7.1.2 has been identified as containing malicious code. This is a supply chain threat where the package itself is intentionally harmful. There is no CVSS score available for this issue, and no known exploits in the wild have been reported to date.

Join the discussion

The Business Directory Plugin – Easy Listing Directories for WordPress plugin for WordPress is vulnerable to time-based SQL Injection via the ‘listingfields’ parameter in all versions up to, and including, 6.4.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

Join the discussion

Showing 1 to 6 of 6 results

Filters:4443
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses