Vulnerability Threats
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Filtered Threats
Click on any threat for detailed analysis and mitigation recommendations
CVE-2026-71832: n/aCVE-2026-71832 0 Aria2 version 1.37.0 and below is affected by a Divide By Zero issue in src/bittorrent_helper.cc, which allows a remote malicious user to cause a Denial of Service Join the discussion | CVE Database V5 | 08/24/2026, 00:00:00 UTC Added: 08/24/2026, 19:07:41 UTC |
CVE-2026-40877: CWE-502: Deserialization of Untrusted Data in Combodo iTopCVE-2026-40877 0 Combodo iTop is a web-based IT service management tool. Prior to 3.2.3, iTop is vulnerable to PHP object injection in the user preference functionality, which can lead to remote code execution. This issue has been fixed in version 3.2.3. Join the discussion | CVE Database V5 | 08/24/2026, 18:57:55 UTC Added: 08/24/2026, 19:07:41 UTC |
CVE-2026-39975: CWE-94: Improper Control of Generation of Code ('Code Injection') in Combodo iTopCVE-2026-39975 0 Combodo iTop is a web-based IT service management tool. Prior to 3.2.3, unauthenticated users could delete the .readonly file on iTop instances, leading to code execution. This file, created during the setup process, prevents users from performing write actions. This issue has been fixed in version 3.2.3. Join the discussion | CVE Database V5 | 08/24/2026, 18:50:48 UTC Added: 08/24/2026, 19:07:41 UTC |
CVE-2026-30864: CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Combodo iTopCVE-2026-30864 0 Combodo iTop is a web-based IT service management tool. Prior to 3.2.3, iTop is vulnerable to Reflected Cross-Site Scripting (XSS) in the dashboard revert functionality. This issue has been fixed in version 3.2.3. Join the discussion | CVE Database V5 | 08/24/2026, 18:52:43 UTC Added: 08/24/2026, 19:07:41 UTC |
CVE-2025-26238: n/aCVE-2025-26238 0 In D-Link DI-8100G 17.12.20A1, the flag parameter in msp_info can be exploited to execute arbitrary code. Join the discussion | CVE Database V5 | 08/24/2026, 00:00:00 UTC Added: 08/24/2026, 19:07:41 UTC |
CVE-2025-26237: n/aCVE-2025-26237 0 A code execution vulnerability exists in the D-Link DI-7001 MINI_5G firmware version 19.10.31A1. The flaw is in the 'flag' parameter of the msp_info component and allows an attacker to execute arbitrary commands. No patch or remediation information is currently available. There is no evidence of exploitation in the wild to date. Join the discussion | CVE Database V5 | 08/24/2026, 00:00:00 UTC Added: 08/24/2026, 18:52:46 UTC |
CVE-2026-78541: CWE-78 Improper neutralization of special elements used in an OS command ('OS command injection') in TP-Link Systems Inc. Archer BE3600 v1CVE-2026-78541 0 CVE-2026-78541 is a stored OS command injection vulnerability in the parent-control module of TP-Link Archer BE3600 v1. An authenticated attacker with administrative access on the local network can store a crafted profile name containing shell metacharacters. This input is later processed unsafely during daily cloud report generation, potentially allowing arbitrary command execution on the device. Exploitation could impact device confidentiality, integrity, and availability. Join the discussion | CVE Database V5 | 08/24/2026, 18:26:11 UTC Added: 08/24/2026, 18:37:38 UTC |
CVE-2026-78417: CWE-345 Insufficient Verification of Data Authenticity in Devolutions Remote Desktop ManagerCVE-2026-78417 0 CVE-2026-78417 is a vulnerability in Devolutions Remote Desktop Manager's IronVNC client that allows insufficient verification of data authenticity. This affects versions 2026.2.17.0 and earlier, and 2026.1.24.0 and earlier. The flaw permits an on-path attacker to intercept and tamper with VNC sessions by exploiting automatic acceptance of the server's RSA key during RSA-AES authentication. Join the discussion | CVE Database V5 | 08/24/2026, 18:26:25 UTC Added: 08/24/2026, 18:37:38 UTC |
CVE-2026-75371: n/aCVE-2026-75371 0 CVE-2026-75371 is an integer handling flaw in the cobs_decode function of SpaceDot AcubeSAT OBC software. This vulnerability allows attackers with physical proximity and UART access to cause a Denial of Service (DoS) by sending crafted input. No patch or official remediation information is currently available. There is no evidence of active exploitation in the wild. The affected software versions are not explicitly stated. Join the discussion | CVE Database V5 | 08/24/2026, 00:00:00 UTC Added: 08/24/2026, 18:37:38 UTC |
CVE-2026-75370: n/aCVE-2026-75370 0 CVE-2026-75370 is an out-of-bounds read/write vulnerability in the MessageParser::parseECSSTCHeader component of SpaceDot AcubeSAT OBC software. This flaw allows an attacker to cause a Denial of Service (DoS) by supplying a specially crafted CAN message. No patch or official remediation information is currently available. There is no CVSS score assigned to this vulnerability, and no known exploits in the wild have been reported. Join the discussion | CVE Database V5 | 08/24/2026, 00:00:00 UTC Added: 08/24/2026, 18:37:38 UTC |
Showing 1 to 10 of 17161 results