Undefined Severity Threats
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Filtered Threats
Click on any threat for detailed analysis and mitigation recommendations
Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none. Join the discussion | GCVE Database | 08/17/2026, 21:31:24 UTC Added: 08/17/2026, 22:33:27 UTC |
0 CVE-2026-60106 is a rejected CVE identifier with no available technical details or description. There is no information on affected versions, impact, or remediation. Join the discussion | GCVE Database | 08/17/2026, 21:31:23 UTC Added: 08/17/2026, 22:33:29 UTC |
0 CVE-2026-60107 is a reserved identifier for a vulnerability that has been rejected and contains no public technical details or impact information. Join the discussion | GCVE Database | 08/17/2026, 21:31:23 UTC Added: 08/17/2026, 22:33:29 UTC |
An out-of-bounds read flaw was found in Samba's Kerberos Key Distribution Center's (KDC) password change (kpasswd) service. When processing malformed ASN.1-encoded Kerberos password change request, Samba server miscalculates the structure size and attempts to read up to six bytes beyond the end of the allocated buffer. While this out-of-bounds read typically results in a harmless decryption failure, if the read hits unmapped memory, it causes the KDC process to crash. An authenticated attacker can send a specially crafted kpasswd request containing malformed ASN.1 data to trigger the out-of-bounds read, which may cause the KDC process to terminate, resulting in a denial of service. Join the discussion | GCVE Database | 07/30/2026, 15:40:11 UTC Added: 07/28/2026, 23:56:43 UTC |
0 A security flaw combining LDAP filter injection and improper authorization checks was found in Samba Active Directory Domain Controller (AD DC). When processing LDAP Compare requests, Samba fails to properly validate user-supplied attribute names and executes the resulting internal database search in a trusted context, bypassing normal Access Control List (ACL) enforcement. An authenticated low-privilege domain user can exploit these flaws to disclose confidential Active Directory attributes that would normally be inaccessible. The disclosed information may be leveraged to derive sensitive authentication material, potentially leading to privilege escalation and complete domain compromise. For example: In deployments configured with Group Managed Service Accounts (gMSAs), an attacker can extract the "msKds-RootKeyData" attribute and derive gMSA passwords offline, potentially leading to complete domain compromise if privileged gMSAs are present. Join the discussion | GCVE Database | 07/30/2026, 15:11:03 UTC Added: 07/28/2026, 23:56:43 UTC |
0 A flaw was found in Samba's internal DNS server where unauthenticated TKEY registration requests were added to the TKEY name cache before being rejected. A remote, unauthenticated attacker can exploit this behavior by sending a large number of TKEY requests with arbitrary names, exhausting the cache and evicting legitimate TKEY entries. This can prevent legitimate TSIG authentication for signed DNS queries, resulting in a denial of service. Join the discussion | GCVE Database | 07/30/2026, 14:01:13 UTC Added: 07/28/2026, 23:56:43 UTC |
samba vulnerabilities (CVE-2026-6949)CVE-2026-6949 0 It was discovered that Samba's pam_winbind incorrectly handled home directory ownership when mkhomedir was enabled. A local attacker could possibly use this issue to cause a denial of service by triggering a change in ownership of the root directory. (CVE-2026-15779) Arjun Basnet, Douglas Bagnall, and Andrew Tridgell discovered that Samba incorrectly handled TSIG packets with name compression. A remote attacker could possibly use this issue to cause Samba to crash, resulting in a denial of service. (CVE-2026-6949) Tristan Madani discovered that Samba incorrectly handled malformed ASN.1 kpasswd packets. An authenticated user could possibly use this issue to cause Samba to crash, resulting in a denial of service. (CVE-2026-58216) Andrew Tridgell and Tristan Madani discovered that Samba incorrectly handled TKEY name registration. A remote attacker could possibly use this issue to exhaust the TKEY name cache, resulting in a denial of service. (CVE-2026-58218) It was discovered that Samba incorrectly handled internal LDB special directory names when processing authenticated LDAP requests. An authenticated user could possibly use this issue to perform unauthorized modifications and gain control of a domain. (CVE-2026-58221) Andrew Tridgell and Tristan Madani discovered that Samba incorrectly handled LDAP Compare requests. An authenticated user could possibly use this issue to obtain sensitive information. (CVE-2026-58222) Tristan Madani, Andrew Tridgell, and Martin Schwenke discovered that the CTDB protocol in Samba had insufficient bounds checking. A remote attacker could possibly use this issue to cause Samba to crash, resulting in a denial of service. (CVE-2026-58224) Join the discussion | GCVE Database | 07/28/2026, 11:50:00 UTC Added: 07/28/2026, 23:58:01 UTC |
Samba AD authenticated LDAP access domain takeover.CVE-2026-58221 0 Samba AD authenticated LDAP access domain takeover. Samba AD low-privilege authenticated LDAP access allows modifications to internal LDB special DNs, which permits a domain takeover. Join the discussion | GCVE Database | 07/28/2026, 10:00:00 UTC Added: 07/28/2026, 23:56:43 UTC |
Linux Kernel: Mehrere SchwachstellenCVE-2024-14040 0 Der Kernel stellt den Kern des Linux Betriebssystems dar. Join the discussion | GCVE Database | 07/26/2026, 22:00:00 UTC Added: 07/26/2026, 22:47:45 UTC |
--- _-= Per source details. Do not edit below this line.=-_ ## Source: kam193 (543206058a0b8e85c8227a0bfdd4752fc61779b24968a0bd5d50ae6b3040387b) During import, the code starts a keylogger and exfiltrates data from cryptowallets. --- Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2026-07-random-ua-generator Reasons (based on the campaign): - keylogger - exfiltration-crypto Join the discussion | GCVE Database | 07/26/2026, 19:36:57 UTC Added: 07/26/2026, 22:46:11 UTC |
No results found