Skip to main content

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Sort: Date Added (Descending)

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

GNU Emacs before 31.2 (and TRAMP through 2.8.2) allows OS command injection via a filename because tramp-user-regexp has an incomplete list of disallowed inputs. NOTE: this issue exists because of an incomplete fix for CVE-2026-79992.

Join the discussion

CVE-2026-108963 is a high-severity vulnerability in databasement before version 1.8.2 that allows authenticated users to achieve remote code execution. The issue arises because certain commands, such as mariadb-dump, are executed with a database name argument that can be controlled by the user. This argument injection enables indirect code execution, for example by writing to files like index.php. The vulnerability is due to improper neutralization of argument delimiters (CWE-88).

Join the discussion

CVE-2026-108768 is a medium severity vulnerability in zhayujie CowAgent up to version 2.2.0. It involves improper resource allocation in the json.loads function of the Streaming Tool-Call Argument Handler component. The vulnerability can be exploited remotely without user interaction or privileges. Public exploit code exists, but there is no vendor response or patch available at this time.

Join the discussion

CVE-2026-108925 is a medium severity cross-site scripting (XSS) vulnerability in the Cohesity NetBackup Administration Console web interface. It involves improper neutralization of script-related HTML tags, allowing an attacker to inject malicious scripts. This affects versions prior to 11.2 of the web interface. The vulnerability has a CVSS 3.1 score of 6.1, indicating a network attack vector with low complexity, no privileges required, but requiring user interaction. The impact includes limited confidentiality and integrity loss without availability impact. No known exploits are reported in the wild. No explicit patch or remediation information is provided in the available data.

Join the discussion

CVE-2026-59508 is an SQL injection vulnerability in Interuse i-Bos version 3.0. It involves improper neutralization of special elements in SQL commands, which could allow an attacker to manipulate database queries. The vulnerability has a medium severity rating with a CVSS score of 5.9. No known exploits are reported in the wild, and no patch or remediation information is currently available.

Join the discussion
0

CVE-2026-19935 is a use-after-free vulnerability in the Zephyr Bluetooth LE host's handling of L2CAP connection-oriented channel (CoC) data when using dynamic PSMs. The issue arises because the system workqueue holds a pending work item referencing a channel object that may be freed or reused during channel teardown, leading to memory corruption or crashes. The vulnerability affects Zephyr versions from 2.0.0 up to and including 4.4.2. The flaw can be triggered remotely by an unauthenticated peer sending specific L2CAP frames. A fix has been implemented that routes the RX work to the Bluetooth workqueue and cancels the pending work item during teardown, preventing use-after-free conditions.

Join the discussion
0

CVE-2026-19740 is a denial-of-service vulnerability in the Zephyr Bluetooth LE Controller's Link Layer Control Procedure (LLCP) implementation. A peer device can exploit this flaw by sending a crafted sequence of LL Control PDUs that causes the controller to leak receive nodes from its limited pool, eventually exhausting resources and rendering Bluetooth inoperable until reboot. The issue affects Zephyr versions from 3.4.0 up to but not including 4.5.0. The vulnerability does not cause memory corruption or information disclosure, only availability impact.

Join the discussion
0

CVE-2026-19739 is a denial of service vulnerability in the Zephyr Bluetooth Link Layer controller affecting versions from 3.4.0 up to but not including 4.5.0. The flaw involves improper handling of retained RX nodes during connection update procedures, which can lead to either a fatal controller error or exhaustion of the controller's RX buffer pool. This can be triggered remotely by an unauthenticated attacker within radio range without requiring pairing, bonding, or encryption. The impact is a persistent denial of service until the device is rebooted, with no memory corruption or data disclosure.

Join the discussion
0

CVE-2026-19738 is a denial-of-service vulnerability in the Zephyr project's Bluetooth Link Layer Control Procedure (LLCP) implementation for Connected Isochronous Stream (CIS) creation. The flaw causes memory nodes to be retained and orphaned without release upon receiving invalid PDUs, leading to resource exhaustion. An attacker within radio range can exploit this without authentication or encryption by sending crafted LL Control PDUs. The impact is limited to availability, causing controller fatal errors or stalled flow control requiring system reboot to recover.

Join the discussion
0

CVE-2026-19737 is a memory-safety vulnerability in the Zephyr project's i2s_esp32 driver affecting versions from 4.4.0 up to but not including 4.5.0. The flaw arises because the driver does not properly check stream pointers for certain I2S directions, leading to a NULL pointer dereference when a user-mode thread triggers an unwired direction. This results in a kernel-mode read from address zero, causing a system halt and denial of service. The vulnerability impacts availability but does not allow information disclosure or code execution. The issue is fixed by adding pointer checks and returning an error for unsupported directions.

Join the discussion

Showing 1 to 10 of 147465 results

Page 1 of 14747
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses