Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.

Critical Severity Threats

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (2):Severity: Critical

Filtered Threats

Click on any threat for detailed analysis and mitigation recommendations

CVE-2026-54213: CWE-284 Improper Access Control in Tobit Laboratories AG TeamDavidCVE-2026-54213
0

Tobit Laboratories AG TeamDavid's Webbox application exposes a functionality that allows the server to be shut down when a specific endpoint (/internalRestart) is accessed. This endpoint is accessible to unauthenticated users over the public Internet. Instead of “restarting”, the server shuts completely down. As a result, a remote attacker can trigger a persistent denial of service by shutting down the web server without requiring authentication. Recovery requires manual administrator intervention to restart the service. This issue affects TeamDavid through Rollout 524.

Join the discussion
CVE-2026-54212: CWE-787 Out-of-bounds write in Tobit Laboratories AG TeamDavidCVE-2026-54212
0

Tobit Laboratories AG TeamDavid's Webbox application implements an API endpoint that is vulnerable to a buffer overflow condition. By submitting a specially crafted JSON body, such as one that is at least 8 characters long and begins with a number, an unauthenticated attacker can cause the server to crash, resulting in denial of service. Depending on the stack state or if a stack canary can be disclosed through another vulnerability, this buffer overflow could potentially lead to remote code execution and full compromise of the server. This issue affects TeamDavid through Rollout 524.

Join the discussion
CVE-2026-54211: CWE-787 Out-of-bounds write in Tobit Laboratories AG TeamDavidCVE-2026-54211
0

Tobit Laboratories AG TeamDavid's Webbox application’s endpoint “//serverClient_close.html” is vulnerable to a buffer overflow vulnerability in multiple form data parameters. By submitting excessively long values in these parameters, an authenticated attacker can trigger a server crash, resulting in denial of service. Depending on the stack state or if a stack canary can be disclosed through another vulnerability, this buffer overflow could potentially be exploited for remote code execution, leading to full compromise of the server. This issue affects TeamDavid through Rollout 524.

Join the discussion
CVE-2026-54210: CWE-787 Out-of-bounds write in Tobit Laboratories AG TeamDavidCVE-2026-54210
0

Tobit Laboratories AG TeamDavid's Webbox application implements various file upload functionalities that are vulnerable to a buffer overflow condition. By specifying an excessively long filename in a file upload request, an unauthenticated attacker can trigger a crash of the server, resulting in a denial of service. Depending on the stack state or if a stack canary can be disclosed through another vulnerability, this buffer overflow could potentially be exploited for remote code execution, leading to full compromise of the server. This issue affects TeamDavid through Rollout 524.

Join the discussion
CVE-2026-54203: CWE-200: Exposure of Sensitive Information to an Unauthorized Actor in Tobit Laboratories AG TeamDavidCVE-2026-54203
0

Memory Leak to an Unauthorized Actor vulnerability in Tobit Laboratories AG TeamDavid's Webbox allows reading of sensitive information. When accessing the URL “/.well-known/mta-sts.”, the application responds with memory. By repeatedly requesting this endpoint, an attacker can access sensitive information, including user passwords. Exploitation does not require authentication. This issue affects TeamDavid through Rollout 524.

Join the discussion
Critical Vulnerabilities Patched With Chrome 151 Update
0

Google released Chrome version 151.0.7922.108/.109 to patch 41 critical and high-severity vulnerabilities, including over two dozen memory safety bugs such as use-after-free and out-of-bounds write flaws. The update addresses six critical issues affecting components like WebGL, Aura, Skia, Views, and the ANGLE graphics engine. No active exploitation in the wild has been reported. Users are advised to update promptly to mitigate risks.

CriticalVulnerability
Join the discussion
CVE-2026-16030: CWE-287 Improper Authentication in MStore APICVE-2026-16030
0

CVE-2026-16030 is an authentication vulnerability in the MStore API WordPress plugin versions before 4.21.0. The plugin fails to properly verify the cryptographic signature of tokens used for phone-based login. This flaw allows unauthenticated attackers who know a registered user's phone number to forge authentication tokens and take over that user's account, including accounts with administrator privileges.

Join the discussion
CVE-2026-15215: CWE-269 Improper Privilege Management in Subscriptions for WooCommerceCVE-2026-15215
0

CVE-2026-15215 is a privilege management vulnerability in the Subscriptions for WooCommerce WordPress plugin before version 2.0.1. It allows users with the Shop Manager role to install and activate arbitrary plugins via a nonce-protected AJAX action without proper capability verification. This flaw can lead to remote code execution by unauthorized users.

Join the discussion
Malicious code in express-chai (npm)
0

The express-chai npm package version 3.7.9 contains malicious code that impersonates an Express logger middleware. It fetches a remote JSON payload from a base64-obfuscated URL and executes code from the payload with full access to the Node.js require function and application context, enabling arbitrary code execution during middleware setup.

Join the discussion
Malicious code in gpt-terminal-cli (npm)
0

The gpt-terminal-cli npm package version 1.0.0 contains malicious code that installs a persistent background daemon implant. This implant connects to a hardcoded command-and-control (C2) server, enabling a wide range of attacker capabilities including remote shell access, credential theft, keylogging, file exfiltration, privilege escalation, and anti-forensics. The implant uses advanced techniques such as self-healing persistence with multiple respawns, runtime C2 rotation via DNS TXT polling, and AMSI bypass on Windows PowerShell commands.

Join the discussion

Showing 1 to 10 of 3339 results

Filters:Severity: Critical
Page 1 of 334
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses