Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.

Low Severity Threats

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (2):Severity: Low

Filtered Threats

Click on any threat for detailed analysis and mitigation recommendations

Arbitrary code execution via crafted project files in Kiro IDECVE-2026-4295
0

CVE-2026-4295 is a vulnerability in Kiro IDE versions prior to 0. 8. 0 that allows arbitrary code execution when a user opens a maliciously crafted project directory. The issue arises from improper enforcement of trust boundaries within the IDE. This vulnerability has been addressed in version 0. 8. 0 of Kiro IDE. Users unable to upgrade immediately are advised to avoid opening untrusted project directories to mitigate risk.

LowVulnerability#rce
Join the discussion
IMDS impersonation
0

AWS has identified a potential Instance Metadata Service (IMDS) impersonation issue affecting IMDSv1 and IMDSv2. This vulnerability could cause customers using AWS tools from non-EC2 compute nodes to interact with unexpected AWS accounts if a third party controls the network and impersonates the IMDS endpoint. The issue arises because IMDS normally runs on a loopback interface within EC2 instances, but outside the AWS data perimeter, a malicious actor with privileged network access could serve fake metadata credentials. AWS recommends following official installation and configuration guides for AWS CLI/SDK and SSM Agent when used outside AWS to mitigate this risk. Additionally, monitoring for unexpected IMDS traffic in on-premises environments is advised to detect potential impersonation attempts. No known exploits in the wild have been reported, and the severity is assessed as low.

LowVulnerability
Join the discussion
Unanchored ACCOUNT_ID webhook filters for CodeBuild
0

Bulletin ID: 2026-002-AWS Scope: AWS Content Type: Informational Publication Date: 2026/01/15 07:03 AM PST Description: A security research team identified a configuration issue affecting the following AWS-managed open source GitHub repositories that could have resulted in the introduction of inappropriate code: - aws-sdk-js-v3 - aws-lc - amazon-corretto-crypto-provider - awslabs/open-data-registry Specifically, researchers identified the above repositories' configured regular expressions for AWS CodeBuild webhook filters intended to limit trusted actor IDs were insufficient, allowing a predictably acquired actor ID to gain administrative permissions for the affected repositories. We can confirm these were project-specific misconfigurations in webhook actor ID filters for these repositories and not an issue in the CodeBuild service itself. The researchers carefully demonstrated the potential to commit inappropriate code, through an empty code commit, to one repository and promptly informed AWS Security of their research activity and its potential negative impact. No inappropriate code was introduced to any of the affected repositories during this security research activity, the demonstrated empty code commit to one repository had no impact to any AWS customer environments and did not impact any AWS services or infrastructure. No customer action is required. Please refer to the article below for the most up-to-date and complete information related to this AWS Security Bulletin.

LowVulnerability#web#rce
Join the discussion
Introducing RAMPART and Clarity: Open source tools to bring safety into Agent development workflow
0

This entry describes the introduction of two open source tools, RAMPART and Clarity, designed to enhance safety in AI agent development workflows. The tools address the evolving capabilities of AI systems in enterprises, which now perform complex tasks such as accessing emails, retrieving CRM records, writing and executing code, and interacting with multiple connected systems. The content is primarily informational about these tools rather than describing a specific vulnerability or exploit. No direct vulnerability details, affected versions, or patch information are provided. The severity is noted as low and no known exploits are reported.

LowVulnerability#rce
Join the discussion
ZDI-26-123: Docker Desktop MCP Server Cleartext Storage of Sensitive Information Vulnerability
0

This vulnerability allows local attackers to disclose sensitive information on affected installations of Docker Desktop. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 5.5.

LowExploit#local
Join the discussion
ZDI-26-130: IceWarp collaboration Directory Traversal Information Disclosure VulnerabilityCVE-2026-2493
0

This vulnerability allows remote attackers to disclose sensitive information on affected installations of IceWarp. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.5. The following CVEs are assigned: CVE-2026-2493.

LowExploit#remote
Join the discussion
ZDI-26-144: Trend Micro Apex Central Hub Server Server-Side Request Forgery VulnerabilityCVE-2025-71205
0

This vulnerability allows remote attackers to disclose sensitive information on affected installations of Trend Micro Apex Central. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 4.4. The following CVEs are assigned: CVE-2025-71205.

LowExploit#remote
Join the discussion
ZDI-26-145: Trend Micro Apex Central Scheduled Update Server-Side Request Forgery VulnerabilityCVE-2025-71206
0

This vulnerability allows remote attackers to disclose sensitive information on affected installations of Trend Micro Apex Central. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 4.4. The following CVEs are assigned: CVE-2025-71206.

LowExploit#remote
Join the discussion
ZDI-26-146: Trend Micro Apex Central Manual Update Server-Side Request Forgery VulnerabilityCVE-2025-71207
0

This vulnerability allows remote attackers to disclose sensitive information on affected installations of Trend Micro Apex Central. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 4.4. The following CVEs are assigned: CVE-2025-71207.

LowExploit#remote
Join the discussion
ZDI-26-149: Trend Micro Cleaner One Pro Link Following Denial-of-Service VulnerabilityCVE-2025-71218
0

This vulnerability allows local attackers to create a denial-of-service condition on affected installations of Trend Micro Cleaner One Pro. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 5.0. The following CVEs are assigned: CVE-2025-71218.

LowExploit#local
Join the discussion

Showing 1 to 10 of 2665 results

Filters:Severity: Low
Page 1 of 267
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses