Skip to main content

Critical Severity Threats

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Severity: Critical

Filtered Threats

Click on any threat for detailed analysis and mitigation recommendations

CVE-2026-94301 is a critical deserialization vulnerability in Apache MINA affecting versions from 2.0.0 up to but not including 2.0.31 and 2.1.0 up to but not including 2.1.15. It stems from an incomplete fix for a previous vulnerability (CVE-2026-47065) where the resolveProxyClass() method override was only applied to the 2.2.X branch, leaving the 2.0.X and 2.1.X branches vulnerable to allow-list bypass. This vulnerability allows remote attackers to execute arbitrary code via deserialization of untrusted data. The CVSS 3.1 base score is 9.8, indicating critical severity with network attack vector, low attack complexity, no privileges or user interaction required, and high impact on confidentiality, integrity, and availability.

Join the discussion

Three Linux kernel vulnerabilities have been identified and added to CISA's Known Exploited Vulnerabilities catalog. These flaws allow local attackers to cause denial-of-service conditions, memory disclosure, or unauthorized memory modification. The vulnerabilities involve issues in the TLS receive path, AF_ALG socket handling, and bridge Netfilter ebtables SNAT target. Federal agencies are urged to patch these vulnerabilities promptly.

CriticalVulnerability#linux#dos
Join the discussion

CVE-2025-12999 is a critical vulnerability in Eclipse Open VSX affecting versions from 0.6.0 up to and including 1.1.2. The vulnerability arises because the application builds absolute URLs in responses from client-supplied X-Forwarded headers without verifying if the sender is a trusted proxy. These responses are cached without including the host in the cache key, allowing an attacker to poison the cache with malicious URLs. This can lead to downstream VS Code-compatible editors fetching and installing malicious VSIX packages. Exploitability depends on deployment topology, specifically whether the server is directly reachable or fronted by a proxy that relays these headers. Workarounds include configuring the proxy to overwrite these headers, restricting direct server access, and flushing caches after configuration changes.

Join the discussion

CVE-2026-94146 is a critical write-what-where vulnerability in BioStar BIOS Update Utility version 1.9.7.3. It arises from improper handling of PhysicalAddress and Size arguments in the IOCTL handler function sub_110BC within the BSMEM64_W10.sys driver. Exploitation requires local access and low privileges. Public exploit code exists, but no vendor response or patch has been provided.

Join the discussion

The Web to Print Online Designer WordPress plugin before 2.15.0 does not validate the type or extension of uploaded files, and hands the token protecting those uploads to any visitor who asks for it, allowing unauthenticated attackers to upload arbitrary files, including PHP ones, and run code on the server.

Join the discussion

CVE-2026-94142 is a critical write-what-where vulnerability in BioStar Temperature Monitor Utility version 1.2.1806.2200. It arises from improper handling of the PhysicalAddress argument in the IOCTL Handler function sub_1105C within the BS_HWMIO64_W10.sys driver file. Exploitation requires local access and can lead to arbitrary memory writes. The vulnerability has been publicly disclosed, but no vendor response or patch is currently available.

Join the discussion

A vulnerability was detected in BioStar VALKYRIE AURORA 2.10.2411.0800. This vulnerability affects the function sub_1105C of the file BS_RVSIO64.sys of the component IOCTL Handler. The manipulation of the argument PhysicalAddress results in write-what-where condition. The attack needs to be approached locally. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

Join the discussion

CVE-2026-94128 is a critical write-what-where vulnerability in BioStar VIVID LED DJ version 4.0.2411.1500. It arises from improper handling of the AssociatedIrp argument in the IOCTL Handler function sub_1105C within the BS_LED64.sys driver file. Exploitation requires local access and can lead to arbitrary memory writes. The vulnerability has been publicly disclosed, but the vendor has not responded or provided a fix. No official patch or remediation guidance is currently available.

Join the discussion
0

CVE-2026-94101 is a critical buffer overflow vulnerability in the Netcore NBR200V2 router firmware version 1.3.241127.071246. The flaw exists in the vlan_load_form_uci function within /usr/bin/routerd, where improper handling of the wan_num argument can lead to a buffer overflow. This vulnerability can be exploited remotely without user interaction. Public exploit code has been disclosed, but the vendor has not responded or provided a fix.

Join the discussion
0

A weakness has been identified in Netcore NBR200V2 1.3.241127.071246. Impacted is the function wan_config_set_vlan of the file /usr/bin/routerd of the component WAN VLAN Reconfiguration. Executing a manipulation of the argument vlan_wanX.ports can lead to buffer overflow. The attack may be performed from remote. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.

Join the discussion

Showing 1 to 10 of 16083 results

Filters:Severity: Critical
Page 1 of 1609
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses