Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.

Low Severity Threats

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (2):Severity: Low

Filtered Threats

Click on any threat for detailed analysis and mitigation recommendations

CVE-2026-50268: CWE-256: Plaintext Storage of a Password in SteeltoeOSS Steeltoe.Configuration.EncryptionCVE-2026-50268
0

Steeltoe.Configuration.Encryption versions 4.0.0 through 4.1.0 contain a vulnerability where configuring RSA encryption with the OAEP algorithm does not actually enable OAEP. Instead, due to an incorrect transformation string in the BouncyCastle library, the OAEP setting falls back to using PKCS#1 v1.5 encryption, which is less secure. This issue is fixed in version 4.2.0.

Join the discussion
CVE-2026-12567: CWE-59 Improper Link Resolution Before File Access ('Link Following') in Black Lantern Security BBOTCVE-2026-12567
0

CVE-2026-12567 is a low-severity vulnerability in Black Lantern Security's BBOT version 2.0.0. The github_workflows module improperly handles user-controlled repository names when constructing local directory paths, failing to validate symbolic links. This allows a local attacker with access to the scan directory to plant a symlink at a predictable output path, causing workflow data to be written to an attacker-chosen location.

Join the discussion
CVE-2026-12566: CWE-918 Server-Side Request Forgery (SSRF) in Black Lantern Security BBOTCVE-2026-12566
0

CVE-2026-12566 is a server-side request forgery (SSRF) vulnerability in Black Lantern Security's BBOT version 2.0.0. The docker_pull module improperly trusts the realm parameter from a Docker registry's WWW-Authenticate header without validation. An attacker positioned as a man-in-the-middle could manipulate this header to redirect authentication requests to a malicious endpoint, potentially exposing authentication tokens. The vulnerability has a low severity score of 3.1 and no known exploits in the wild. No official patch or remediation guidance is currently available.

Join the discussion
CVE-2026-43122CVE-2026-43122
0

CVE-2026-43122 is a rejected vulnerability entry with no available technical details or impact information. There is no CVSS score or remediation guidance provided.

Join the discussion
CVE-2026-43423CVE-2026-43423
0

CVE-2026-43423 is a rejected vulnerability entry with no available technical details or description. There is no information on affected versions, impact, or remediation.

Join the discussion
CVE-2026-43422CVE-2026-43422
0

CVE-2026-43422 is a rejected vulnerability entry with no available technical details, description, or confirmed impact. There is no information on affected versions, exploitation, or remediation.

Join the discussion
CVE-2026-31688CVE-2026-31688
0

CVE-2026-31688 is a vulnerability record that has been rejected by the CVE program. There is no technical description, no CVSS score, no affected versions, and no remediation information available. The CVE entry is marked as rejected, indicating it is not recognized as a valid vulnerability.

Join the discussion
CVE-2025-38553CVE-2025-38553
0

CVE-2025-38553 is a vulnerability record that has been rejected by the assigning authority and contains no technical details or impact information.

Join the discussion
CVE-2026-39199: CWE-787 Out-of-bounds Write in Snes9X team Snes9XCVE-2026-39199
0

snes9x 1.63 allows an out-of-bounds write and denial of service via a crafted .ups file.

Join the discussion
CVE-2026-35068: CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in Dell PowerFlexCVE-2026-35068
0

Dell PowerFlex Manager, version(s) [Versions], contain(s) an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged attacker with adjacent network access could potentially exploit this vulnerability, leading to information disclosure.

Join the discussion

Showing 1 to 10 of 2913 results

Filters:Severity: Low
Page 1 of 292
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses