Undefined Severity Threats
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Filtered Threats
Click on any threat for detailed analysis and mitigation recommendations
CVE-2026-52100: n/aCVE-2026-52100 0 Cross Site Request Forgery vulnerability in andreimarcu linux-server v.1.0 through v.2.3.8 allows a remote attacker to execute arbitrary code via the uploadPutHandler function Join the discussion | CVE Database V5 | 07/14/2026, 00:00:00 UTC Added: 07/14/2026, 21:18:09 UTC |
CVE-2026-62393: CWE-280 Improper Handling of Insufficient Permissions or Privileges in Apache Software Foundation Apache KylinCVE-2026-62393 0 Improper Handling of Insufficient Permissions or Privileges vulnerability in Apache Kylin. Improper authorization in job information retrieval, where an attacker may get access to unauthorized jobs in other projects. This issue affects Apache Kylin: from 4 through 5.0.3. Users are recommended to upgrade to version 5.0.4, which fixes the issue. Join the discussion | CVE Database V5 | 07/14/2026, 12:19:27 UTC Added: 07/14/2026, 12:48:12 UTC |
MAL-2026-10444: Malicious code in markable-table (npm) 0 --- _-= Per source details. Do not edit below this line.=-_ ## Source: amazon-inspector (fd358271f202636f12507f09da4e8f00c900ba46c9dca25a5a0526d35b75bf1d) [email protected] declares scripts.preinstall = 'node index.d.js'. index.d.js base64-decodes an embedded payload and invokes it through an identifier reconstructed from a char-code array ([101,118,97,108] = 'eval'), hiding the 'eval' token from plain-text scanners. The decoded payload fetches JavaScript from https://everydaynodechecker-39143n.vercel.app/api/key?mem=root0 and eval()s the response body at npm install time, giving the operator of that endpoint arbitrary code execution on any machine that runs `npm install`. The remote-fetch-and-eval, the obfuscation of both the 'eval' identifier and the destination URL, the non-first-party Vercel host, and the mismatch with the package's advertised markdown-table purpose (and typosquat of the popular 'markdown-table' package) together match the install-time-RCE dropper pattern. ## Source: ghsa-malware (d4db694f1a9db0f84f99ffe21a31c0a526f67dafe412b53dcee0c75eb79678e1) Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it. Join the discussion | GCVE Database | 07/13/2026, 14:02:53 UTC Added: 07/14/2026, 09:20:10 UTC |
xfrm: prevent policy_hthresh.work from racing with netns teardownCVE-2026-31516 0 To determine the support lifecycle for your software, see the Microsoft Support Lifecycle: https://support.microsoft.com/lifecycle Join the discussion | GCVE Database | 04/02/2026, 00:00:00 UTC Added: 06/29/2026, 22:11:24 UTC |
drm, fbcon, vga_switcheroo: Avoid race condition in fbcon setupCVE-2025-68296 0 To determine the support lifecycle for your software, see the Microsoft Support Lifecycle: https://support.microsoft.com/lifecycle Join the discussion | GCVE Database | 12/02/2025, 00:00:00 UTC Added: 06/26/2026, 13:36:31 UTC |
landlock: Fix handling of disconnected directoriesCVE-2025-68736 0 To determine the support lifecycle for your software, see the Microsoft Support Lifecycle: https://support.microsoft.com/lifecycle Join the discussion | GCVE Database | 12/02/2025, 00:00:00 UTC Added: 06/26/2026, 13:36:31 UTC |
IBM WebSphere Application Server: Mehrere SchwachstellenCVE-2026-10845 0 IBM WebSphere Application Server ist ein J2EE-Applikationsserver. Join the discussion | GCVE Database | 06/17/2026, 22:00:00 UTC Added: 06/26/2026, 02:42:58 UTC |
CVE Database V5 | 06/24/2026, 22:47:07 UTC | |
Flowise: Mehrere Schwachstellen ermöglichen Umgehen von SicherheitsvorkehrungenCVE-2025-71337 0 Flowise ist eine Benutzeroberfläche zur Erstellung von LLMs (Large Language Model). Join the discussion | GCVE Database | 11/12/2025, 23:00:00 UTC Added: 06/24/2026, 16:59:32 UTC |
CVE Database V5 | 06/24/2026, 15:39:25 UTC |
Showing 1 to 10 of 40 results