Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Search Results: "index.ts"
Click on any threat for detailed analysis and mitigation recommendations
CVE-2026-11436: Cross Site Scripting in Mage AICVE-2026-11436 0 A vulnerability was detected in Mage AI up to 0.9.79. This impacts the function useMutation of the file mage_ai/frontend/components/Sessions/SignForm/index.tsx of the component Sign-in Flow. Performing a manipulation of the argument query.redirect_url results in cross site scripting. Remote exploitation of the attack is possible. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. Join the discussion | CVE Database V5 | 06/06/2026, 15:45:07 UTC Added: 06/06/2026, 16:05:56 UTC |
CVE-2026-10278: Path Traversal in ishayoyo excel-mcpCVE-2026-10278 0 A vulnerability was determined in ishayoyo excel-mcp up to 1.0.2. Impacted is an unknown function of the file src/index.ts of the component read_file/write_file. Executing a manipulation of the argument filePath/outputPath can lead to path traversal. It is possible to launch the attack remotely. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through an issue report but has not responded yet. Join the discussion | CVE Database V5 | 06/01/2026, 17:30:10 UTC Added: 06/01/2026, 19:52:32 UTC |
CVE-2026-10276: Server-Side Request Forgery in hekmon8 Jenkins-server-mcpCVE-2026-10276 0 CVE-2026-10276 is a server-side request forgery (SSRF) vulnerability in hekmon8 Jenkins-server-mcp version 0.1.0. The flaw exists in the jobPath function within the src/index.ts file, affecting components related to getting build status, build logs, and triggering builds. This vulnerability can be exploited remotely without user interaction and has been publicly disclosed. The vendor has not yet responded or provided a fix. The CVSS 4.0 base score is 5.3, indicating a medium severity level. Join the discussion | CVE Database V5 | 06/01/2026, 17:00:11 UTC Added: 06/01/2026, 19:52:32 UTC |
CVE-2026-9472: Path Traversal in dazeb markdown-downloaderCVE-2026-9472 0 A flaw has been found in dazeb markdown-downloader up to 3d4394b34b6c99d81af817623af55e3384df5a6a. Affected is the function download_markdown/list_downloaded_files/create_subdirectory of the file src/index.ts. Executing a manipulation can lead to path traversal. The attack can be launched remotely. The exploit has been published and may be used. This product does not use versioning. This is why information about affected and unaffected releases are unavailable. The project was informed of the problem early through an issue report but has not responded yet. Join the discussion | CVE Database V5 | 05/25/2026, 16:00:17 UTC Added: 05/25/2026, 16:25:00 UTC |
CVE-2026-9468: Path Traversal in dazeb cline-mcp-memory-bankCVE-2026-9468 0 CVE-2026-9468 is a medium-severity path traversal vulnerability in the dazeb cline-mcp-memory-bank project. The flaw exists in the handleInitializeMemoryBank function in src/index.ts, where manipulation of the projectPath argument allows an attacker to perform path traversal. This vulnerability can be exploited remotely and a public exploit is available. The project uses a rolling release system, and no specific patched version has been disclosed. The vendor has not yet responded to the issue report, and no official fix or mitigation guidance is currently available. Join the discussion | CVE Database V5 | 05/25/2026, 15:00:17 UTC Added: 05/25/2026, 15:40:00 UTC |
CVE-2026-7730: OS Command Injection in privsim mcp-test-runnerCVE-2026-7730 0 A weakness has been identified in privsim mcp-test-runner 0.2.0. Impacted is the function child_process.spawn of the file src/index.ts of the component MCP Interface. Executing a manipulation of the argument command can lead to os command injection. The attack may be launched remotely. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet. Join the discussion | CVE Database V5 | 05/04/2026, 04:00:19 UTC Added: 05/04/2026, 04:22:16 UTC |
CVE-2026-7729: Server-Side Request Forgery in pixelsock directus-mcpCVE-2026-7729 0 A security flaw has been discovered in pixelsock directus-mcp 1.0.0. This issue affects the function validateUrl of the file index.ts of the component MCP Interface. Performing a manipulation of the argument fileUrl results in server-side request forgery. The attack may be initiated remotely. The exploit has been released to the public and may be used for attacks. The pull request to fix this issue awaits acceptance. Join the discussion | CVE Database V5 | 05/04/2026, 03:45:14 UTC Added: 05/04/2026, 04:22:16 UTC |
CVE-2026-7653: OS Command Injection in r-huijts mcp-server-rijksmuseumCVE-2026-7653 0 A security flaw has been discovered in r-huijts mcp-server-rijksmuseum up to 1.0.4. Affected is the function open_image_in_browser of the file src/index.ts of the component MCP Interface. Performing a manipulation of the argument imageUrl results in os command injection. The attack is possible to be carried out remotely. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet. Join the discussion | CVE Database V5 | 05/02/2026, 15:30:19 UTC Added: 05/02/2026, 15:51:23 UTC |
CVE-2026-7642: OS Command Injection in pskill9 website-downloaderCVE-2026-7642 0 A vulnerability was detected in pskill9 website-downloader up to 0.1.0. This affects the function download_website of the file src/index.ts of the component MCP Interface. Performing a manipulation of the argument outputPath results in os command injection. The attack may be initiated remotely. The exploit is now public and may be used. The project was informed of the problem early through an issue report but has not responded yet. Join the discussion | CVE Database V5 | 05/02/2026, 14:30:13 UTC Added: 05/02/2026, 14:51:23 UTC |
CVE-2026-7627: Path Traversal in 8nite metatrader-4-mcpCVE-2026-7627 0 A security vulnerability has been detected in 8nite metatrader-4-mcp 1.0.0. This vulnerability affects the function CallToolRequestSchema of the file src/index.ts of the component sync_ea_from_file. Such manipulation of the argument ea_name leads to path traversal. The attack can be launched remotely. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through an issue report but has not responded yet. Join the discussion | CVE Database V5 | 05/02/2026, 11:00:14 UTC Added: 05/02/2026, 11:22:17 UTC |
Showing 1 to 10 of 34 results