Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.

Vulnerability Threats

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (2):Type: Vulnerability

Filtered Threats

Click on any threat for detailed analysis and mitigation recommendations

CVE-2026-71832: n/aCVE-2026-71832
0

Aria2 version 1.37.0 and below is affected by a Divide By Zero issue in src/bittorrent_helper.cc, which allows a remote malicious user to cause a Denial of Service

Join the discussion
CVE-2026-40877: CWE-502: Deserialization of Untrusted Data in Combodo iTopCVE-2026-40877
0

Combodo iTop is a web-based IT service management tool. Prior to 3.2.3, iTop is vulnerable to PHP object injection in the user preference functionality, which can lead to remote code execution. This issue has been fixed in version 3.2.3.

Join the discussion
CVE-2026-39975: CWE-94: Improper Control of Generation of Code ('Code Injection') in Combodo iTopCVE-2026-39975
0

Combodo iTop is a web-based IT service management tool. Prior to 3.2.3, unauthenticated users could delete the .readonly file on iTop instances, leading to code execution. This file, created during the setup process, prevents users from performing write actions. This issue has been fixed in version 3.2.3.

Join the discussion
CVE-2026-30864: CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Combodo iTopCVE-2026-30864
0

Combodo iTop is a web-based IT service management tool. Prior to 3.2.3, iTop is vulnerable to Reflected Cross-Site Scripting (XSS) in the dashboard revert functionality. This issue has been fixed in version 3.2.3.

Join the discussion
CVE-2025-26238: n/aCVE-2025-26238
0

In D-Link DI-8100G 17.12.20A1, the flag parameter in msp_info can be exploited to execute arbitrary code.

Join the discussion
CVE-2025-26237: n/aCVE-2025-26237
0

A code execution vulnerability exists in the D-Link DI-7001 MINI_5G firmware version 19.10.31A1. The flaw is in the 'flag' parameter of the msp_info component and allows an attacker to execute arbitrary commands. No patch or remediation information is currently available. There is no evidence of exploitation in the wild to date.

Join the discussion
CVE-2026-78541: CWE-78 Improper neutralization of special elements used in an OS command ('OS command injection') in TP-Link Systems Inc. Archer BE3600 v1CVE-2026-78541
0

CVE-2026-78541 is a stored OS command injection vulnerability in the parent-control module of TP-Link Archer BE3600 v1. An authenticated attacker with administrative access on the local network can store a crafted profile name containing shell metacharacters. This input is later processed unsafely during daily cloud report generation, potentially allowing arbitrary command execution on the device. Exploitation could impact device confidentiality, integrity, and availability.

Join the discussion
CVE-2026-78417: CWE-345 Insufficient Verification of Data Authenticity in Devolutions Remote Desktop ManagerCVE-2026-78417
0

CVE-2026-78417 is a vulnerability in Devolutions Remote Desktop Manager's IronVNC client that allows insufficient verification of data authenticity. This affects versions 2026.2.17.0 and earlier, and 2026.1.24.0 and earlier. The flaw permits an on-path attacker to intercept and tamper with VNC sessions by exploiting automatic acceptance of the server's RSA key during RSA-AES authentication.

Join the discussion
CVE-2026-75371: n/aCVE-2026-75371
0

CVE-2026-75371 is an integer handling flaw in the cobs_decode function of SpaceDot AcubeSAT OBC software. This vulnerability allows attackers with physical proximity and UART access to cause a Denial of Service (DoS) by sending crafted input. No patch or official remediation information is currently available. There is no evidence of active exploitation in the wild. The affected software versions are not explicitly stated.

Join the discussion
CVE-2026-75370: n/aCVE-2026-75370
0

CVE-2026-75370 is an out-of-bounds read/write vulnerability in the MessageParser::parseECSSTCHeader component of SpaceDot AcubeSAT OBC software. This flaw allows an attacker to cause a Denial of Service (DoS) by supplying a specially crafted CAN message. No patch or official remediation information is currently available. There is no CVSS score assigned to this vulnerability, and no known exploits in the wild have been reported.

Join the discussion

Showing 1 to 10 of 17161 results

Filters:Type: Vulnerability
Page 1 of 1717
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses