Low Severity Threats
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Filtered Threats
Click on any threat for detailed analysis and mitigation recommendations
Arbitrary code execution via crafted project files in Kiro IDECVE-2026-4295 0 CVE-2026-4295 is a vulnerability in Kiro IDE versions prior to 0. 8. 0 that allows arbitrary code execution when a user opens a maliciously crafted project directory. The issue arises from improper enforcement of trust boundaries within the IDE. This vulnerability has been addressed in version 0. 8. 0 of Kiro IDE. Users unable to upgrade immediately are advised to avoid opening untrusted project directories to mitigate risk. Join the discussion | AWS Security Bulletins | 03/17/2026, 19:20:39 UTC Added: 05/26/2026, 20:30:37 UTC |
IMDS impersonation 0 AWS has identified a potential Instance Metadata Service (IMDS) impersonation issue affecting IMDSv1 and IMDSv2. This vulnerability could cause customers using AWS tools from non-EC2 compute nodes to interact with unexpected AWS accounts if a third party controls the network and impersonates the IMDS endpoint. The issue arises because IMDS normally runs on a loopback interface within EC2 instances, but outside the AWS data perimeter, a malicious actor with privileged network access could serve fake metadata credentials. AWS recommends following official installation and configuration guides for AWS CLI/SDK and SSM Agent when used outside AWS to mitigate this risk. Additionally, monitoring for unexpected IMDS traffic in on-premises environments is advised to detect potential impersonation attempts. No known exploits in the wild have been reported, and the severity is assessed as low. LowVulnerability Join the discussion | AWS Security Bulletins | 10/08/2025, 18:28:31 UTC Added: 05/26/2026, 20:30:34 UTC |
Unanchored ACCOUNT_ID webhook filters for CodeBuild 0 Bulletin ID: 2026-002-AWS Scope: AWS Content Type: Informational Publication Date: 2026/01/15 07:03 AM PST Description: A security research team identified a configuration issue affecting the following AWS-managed open source GitHub repositories that could have resulted in the introduction of inappropriate code: - aws-sdk-js-v3 - aws-lc - amazon-corretto-crypto-provider - awslabs/open-data-registry Specifically, researchers identified the above repositories' configured regular expressions for AWS CodeBuild webhook filters intended to limit trusted actor IDs were insufficient, allowing a predictably acquired actor ID to gain administrative permissions for the affected repositories. We can confirm these were project-specific misconfigurations in webhook actor ID filters for these repositories and not an issue in the CodeBuild service itself. The researchers carefully demonstrated the potential to commit inappropriate code, through an empty code commit, to one repository and promptly informed AWS Security of their research activity and its potential negative impact. No inappropriate code was introduced to any of the affected repositories during this security research activity, the demonstrated empty code commit to one repository had no impact to any AWS customer environments and did not impact any AWS services or infrastructure. No customer action is required. Please refer to the article below for the most up-to-date and complete information related to this AWS Security Bulletin. Join the discussion | AWS Security Bulletins | 01/15/2026, 15:43:30 UTC Added: 05/26/2026, 20:30:32 UTC |
Introducing RAMPART and Clarity: Open source tools to bring safety into Agent development workflow 0 This entry describes the introduction of two open source tools, RAMPART and Clarity, designed to enhance safety in AI agent development workflows. The tools address the evolving capabilities of AI systems in enterprises, which now perform complex tasks such as accessing emails, retrieving CRM records, writing and executing code, and interacting with multiple connected systems. The content is primarily informational about these tools rather than describing a specific vulnerability or exploit. No direct vulnerability details, affected versions, or patch information are provided. The severity is noted as low and no known exploits are reported. Join the discussion | Microsoft Security Blog | 05/20/2026, 15:00:00 UTC Added: 05/26/2026, 20:27:45 UTC |
ZDI-26-123: Docker Desktop MCP Server Cleartext Storage of Sensitive Information Vulnerability 0 This vulnerability allows local attackers to disclose sensitive information on affected installations of Docker Desktop. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 5.5. Join the discussion | Zero Day Initiative | 02/23/2026, 06:00:00 UTC Added: 05/26/2026, 20:03:32 UTC |
ZDI-26-130: IceWarp collaboration Directory Traversal Information Disclosure VulnerabilityCVE-2026-2493 0 This vulnerability allows remote attackers to disclose sensitive information on affected installations of IceWarp. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.5. The following CVEs are assigned: CVE-2026-2493. Join the discussion | Zero Day Initiative | 02/25/2026, 06:00:00 UTC Added: 05/26/2026, 20:03:32 UTC |
ZDI-26-144: Trend Micro Apex Central Hub Server Server-Side Request Forgery VulnerabilityCVE-2025-71205 0 This vulnerability allows remote attackers to disclose sensitive information on affected installations of Trend Micro Apex Central. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 4.4. The following CVEs are assigned: CVE-2025-71205. Join the discussion | Zero Day Initiative | 03/03/2026, 06:00:00 UTC Added: 05/26/2026, 20:03:32 UTC |
ZDI-26-145: Trend Micro Apex Central Scheduled Update Server-Side Request Forgery VulnerabilityCVE-2025-71206 0 This vulnerability allows remote attackers to disclose sensitive information on affected installations of Trend Micro Apex Central. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 4.4. The following CVEs are assigned: CVE-2025-71206. Join the discussion | Zero Day Initiative | 03/03/2026, 06:00:00 UTC Added: 05/26/2026, 20:03:32 UTC |
ZDI-26-146: Trend Micro Apex Central Manual Update Server-Side Request Forgery VulnerabilityCVE-2025-71207 0 This vulnerability allows remote attackers to disclose sensitive information on affected installations of Trend Micro Apex Central. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 4.4. The following CVEs are assigned: CVE-2025-71207. Join the discussion | Zero Day Initiative | 03/03/2026, 06:00:00 UTC Added: 05/26/2026, 20:03:32 UTC |
ZDI-26-149: Trend Micro Cleaner One Pro Link Following Denial-of-Service VulnerabilityCVE-2025-71218 0 This vulnerability allows local attackers to create a denial-of-service condition on affected installations of Trend Micro Cleaner One Pro. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 5.0. The following CVEs are assigned: CVE-2025-71218. Join the discussion | Zero Day Initiative | 03/03/2026, 06:00:00 UTC Added: 05/26/2026, 20:03:32 UTC |
Showing 1 to 10 of 2665 results