Low Severity Threats
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Filtered Threats
Click on any threat for detailed analysis and mitigation recommendations
A vulnerability was found in itsourcecode Sales and Inventory System 1.0. (CVE-2026-78656)CVE-2026-78656 0 A vulnerability was found in itsourcecode Sales and Inventory System 1.0. Affected is an unknown function of the file /pages/cust_del.php. The manipulation of the argument ID results in sql injection. The attack can be executed remotely. The exploit has been made public and could be used. Join the discussion | GCVE Database | 08/25/2026, 09:30:37 UTC Added: 08/25/2026, 13:38:41 UTC |
Org.keycloak/keycloak-services: webauthn attestation statement verification bypass (CVE-2025-12150)CVE-2025-12150 0 A flaw was found in Keycloak’s WebAuthn registration component. This vulnerability allows an attacker to bypass the configured attestation policy and register untrusted or forged authenticators via submission of an attestation object with fmt: "none", even when the realm is configured to require direct attestation. This can lead to weakened authentication integrity and unauthorized authenticator registration. Join the discussion | GCVE Database | 08/25/2026, 11:41:28 UTC Added: 08/25/2026, 13:38:28 UTC |
A flaw was found in gnutls. The PKCS#7 padding check, performed during decryption, was not constant-time. (CVE-2026-5419)CVE-2026-5419 0 A flaw was found in gnutls. The PKCS#7 padding check, performed during decryption, was not constant-time. This timing side-channel could allow a remote attacker to potentially leak sensitive information about the padding bytes through observable timing differences. This vulnerability is a form of information disclosure. Join the discussion | GCVE Database | 06/01/2026, 21:30:45 UTC Added: 08/25/2026, 13:38:15 UTC |
CVE-2026-21758: CWE-200 Exposure of Sensitive Information to an Unauthorized Actor in HCL Software HiveCVE-2026-21758 0 HCL Hive is affected by an information disclosure vulnerability, which could lead to an attacker gathering sensitive information about the host environment. Join the discussion | CVE Database V5 | 08/25/2026, 10:49:13 UTC Added: 08/25/2026, 11:07:54 UTC |
CVE-2026-66882: CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in team-alembic ash_authenticationCVE-2026-66882 0 Improper Neutralization of Input During Web Page Generation (XSS) vulnerability in team-alembic AshAuthentication allows reflected cross-site scripting via the confirmation and magic link interaction forms. When a strategy is configured with require_interaction? set to true, AshAuthentication serves an intermediate HTML page asking the user to confirm the action by submitting a form. Both such pages embed a request parameter directly into a hidden input's value attribute without HTML escaping: lib/ash_authentication/add_ons/confirmation/confirmation_form.html.eex interpolates the confirm parameter, and lib/ash_authentication/strategies/magic_link/sign_in_form.html.eex interpolates the magic link token parameter. These templates are compiled with EEx.function_from_file/3 using plain <%= %> expressions, which perform no escaping, so the parameter is reflected verbatim. Neither accept handler validates the value before rendering it. AshAuthentication.AddOn.Confirmation.Plug.accept/2 only checks that a confirm key is present, and AshAuthentication.Strategy.MagicLink.Plug.accept/2 reads the parameter directly, so no token signature is verified at this stage and arbitrary attacker-supplied text reaches the template. An unauthenticated attacker can therefore craft a URL whose parameter terminates the attribute and injects markup, for example a quote followed by a <script> element. Because the accept phase is served over GET, loading the crafted link is sufficient; no form submission or prior authentication is required. The injected script executes in the origin of the application embedding AshAuthentication, giving it access to that origin's cookies, session, and same-origin responses. Since these pages are part of the authentication flow, a victim following what appears to be a legitimate confirmation or sign-in link is a plausible target. This issue affects ash_authentication: from 4.8.0 before 4.14.2 and from 5.0.0-rc.0 before 5.0.0-rc.13. Join the discussion | CVE Database V5 | 08/25/2026, 08:03:47 UTC Added: 08/25/2026, 08:22:40 UTC |
CVE Database V5 | 08/25/2026, 06:09:16 UTC | |
ISC Stormcast For Tuesday, August 25th, 2026 https://isc.sans.edu/podcastdetail/10066, (Tue, Aug 25th) 0 This entry is a daily update from the SANS Internet Storm Center (ISC) titled 'ISC Stormcast For Tuesday, August 25th, 2026.' It provides general information and links to a podcast and classes but does not contain any specific security threat or vulnerability details. LowNews Join the discussion | SANS ISC Handlers Diary | 08/25/2026, 02:00:03 UTC Added: 08/25/2026, 02:07:17 UTC |
CVE-2026-16434: Improper Input Validation in vrana adminerCVE-2026-16434 0 Adminer 4.6.0 through 5.5.0 (fixed in 5.5.1) contains an incomplete fix for a prior X-Forwarded-Prefix vulnerability (GHSA-8478-xrj3-h9c2). The validation guard (bootstrap.inc.php) only rejects prefixes matching ^/[^/], blocking //evil.com but allowing values such as /\evil.com whose second character is a backslash. Because browsers normalize backslash to forward slash, a network-path reference survives into REQUEST_URI and reaches cookie_path(), affecting the Set-Cookie Path attribute. Exploitation requires that clients can set the X-Forwarded-Prefix header (a misconfigured or absent reverse proxy). Impact is limited to anomalous cookie-path scoping. Join the discussion | CVE Database V5 | 08/25/2026, 01:29:57 UTC Added: 08/25/2026, 01:52:56 UTC |
CVE Database V5 | 08/24/2026, 18:37:38 UTC | |
CVE Database V5 | 08/24/2026, 18:37:38 UTC |
Showing 1 to 10 of 1148 results