Skip to content
Product
Use it
Threat intelligence API
Free key, 70+ endpoints, OpenAPI. The product.
Get started
Pick your stack, make your first call.
Live feed
The console: incidents, filters, entities, search.
Recipes
Runnable examples for the free key.
Free feeds
RSS, ransomware feed, IOC blocklist, MISP — no key.
CLI & agents
tc from a terminal; agent keys with scoped budgets.
The data
Incident records
900 articles a day become ~70 scored incidents.
Dark web
First-party leak-site collection: victims, groups, markets.
Validated IOCs
Indicators with a false-positive gate; STIX, MISP, CSV.
Vulnerabilities
CVEs with EPSS, KEV and exploit status.
Entity graph
Actors, malware, CVEs, companies — pivotable.
For teams
For service providers
Per-client feeds, alerts and branded digests.
Use cases
How teams and builders use the corpus.
About ThreatCluster
What it is and how it is built.
Pricing
Docs
Reference
OpenAPI (Swagger)
Every endpoint, parameter and response model.
ReDoc
The same reference, long-form.
Examples on GitHub
curl, Python and Node quickstarts; daily spec snapshot.
Guides
Quickstart & plans
Key, scopes, budgets, tiers.
Integrations
Splunk, Sentinel, Elastic, agents and terminals, step by step
Export formats
STIX 2.1, MISP, CSV, text.
CLI setup
Install, log in, wire an agent.
No results found
Sign in
Get a free key
No results found
Product
Threat intelligence API
Get started
Live feed
Recipes
Free feeds
CLI & agents
The data
Incident records
Dark web
Validated IOCs
Vulnerabilities
Entity graph
For teams
For service providers
Use cases
About ThreatCluster
Docs
OpenAPI (Swagger)
ReDoc
Examples on GitHub
Quickstart & plans
Integrations
Export formats
CLI setup
Pricing
Contact
Get a free key
Sign in
Back
Cwe-119 - Improper Restriction Of Operations Within Memory Buffer
CWE Weakness
Threat entity extracted from intelligence sources
Sep 15: 2 mentions
Sep 16: 1 mention
Sep 17: 0 mentions
Sep 18: 0 mentions
Sep 19: 0 mentions
Sep 20: 1 mention
Sep 21: 0 mentions
Sep 15
Sep 18
Sep 21
Entities
›
cwe
›
Cwe-119 - Improper Restriction Of Operations Within Memory Buffer
Frequency
49
occurrences
First Seen
April 19, 2026
Last Seen
September 20, 2026
API
Overview
Recent Events
Profile
Profile
MITRE ATT&CK
1 / 2
Malware
WeWorm
Tools
Chrome
Nginx
CVEs
CVE-2026-27784
CVE-2026-42945
CVE-2026-32647
CVE-2026-27651
CVE-2026-27654
CVE-2026-1642
CVE-2026-9637
CVE-2026-12806
Campaigns
Zoomsday
TeamPCP Supply Chain Attacks
Regions
China
Russia
Ukraine
United States
Taiwan
-
REC
Recon
No techniques detected
-
RD
Resource Dev
No techniques detected
2
IA
Initial Access
T1190 - Exploit Public-Facing Application
T1566.001 - Spearphishing Attachment
2
EX
Execution
T1059 - Command and Scripting Interpreter
T1203 - Exploitation for Client Execution
-
PE
Persistence
No techniques detected
1
PE
Priv Esc
T1068 - Exploitation for Privilege Escalation
-
DE
Defense Evasion
No techniques detected
-
CA
Cred Access
No techniques detected
-
DI
Discovery
No techniques detected
-
LM
Lateral Mov
No techniques detected
-
CO
Collection
No techniques detected
-
C2
C2
No techniques detected
-
EX
Exfil
No techniques detected
-
IM
Impact
No techniques detected
5
techniques detected across
3
tactics
Related Clusters (45)
F5 Issues Critical Patches for NGINX Vulnerabilities Allowing Remote Code Execution
Jun 18
·
24 sources
80
Critical OVERPASS Vulnerability in SAP Kernel Requires Immediate Action
Sep 8
·
22 sources
76
Cloud Atlas APT Group Exploits CVE-2018-0802 and Modifies termsrv.dll for RDP Access
May 25
·
4 sources
76
Cisco Issues Critical Security Advisories for IOS XE and SD-WAN Vulnerabilities
Aug 6
·
43 sources
74
Critical OpenJPEG Vulnerability in Ubuntu Systems
May 7
·
2 sources
74
Critical libpng Vulnerabilities Affecting Multiple Ubuntu Releases
May 7
·
2 sources
74
Critical Stack-based Buffer Overflow Vulnerability in Tenda G0 Devices
Aug 14
·
4 sources
74
Critical Buffer Overflow Vulnerabilities in glibc Affect Fedora Systems
May 3
·
2 sources
74
Critical NGINX Vulnerability CVE-2026-42533 Poses RCE and DoS Risks
Jul 16
·
36 sources
74
Multiple CVEs Disclosed on September 8, 2026, Affecting Microsoft Products
Sep 8
·
927 sources
74
Critical Android Vulnerabilities Patched in September 2026 Update
Sep 9
·
60 sources
73
Microsoft September 2026 Patch Tuesday: Record 974 Vulnerabilities Addressed
Sep 8
·
98 sources
73
Critical Linux Vulnerability 'Copy Fail' Grants Root Access Across Major Distros
Apr 30
·
227 sources
73
Exploitation of Citrix NetScaler Authentication Bypass Vulnerability CVE-2026-19490
Sep 4
·
29 sources
73
Critical Code Execution Vulnerabilities in Oracle Linux nginx
Jun 25
·
12 sources
73
Critical Vulnerabilities in HPE Aruba EdgeConnect SD-WAN Exploitable
4d ago
·
5 sources
72
Critical Zoom Vulnerabilities Enable Remote Code Execution via AI-Driven Exploits
Aug 11
·
46 sources
72
WhatsApp Spyware Exploit via Phone Calls Poses Serious Threat
Jun 10
·
2 sources
72
Critical Buffer Overflow Vulnerability in H3C Magic B0 Devices
Apr 19
·
3 sources
72
Critical Buffer Overflow Vulnerability in Edimax BR-6478AC V2 Disclosed
Jun 21
·
7 sources
71
Multiple Vulnerabilities Discovered in macOS Tahoe and WebKit
Aug 19
·
13 sources
71
Microsoft June 2026 Patch Tuesday: Record 206 Vulnerabilities Addressed
Jun 9
·
57 sources
71
Cisco ClamAV Vulnerabilities Allow Remote DoS Attacks
Aug 11
·
13 sources
71
Critical Vulnerability in GDK-PixBuf Affects Multiple Ubuntu Releases
Jun 9
·
2 sources
71
2026 Smartphone Security Threats: Zero-Click Exploits and Banking Trojans Rise
May 23
·
2 sources
70
AI Worms Exploit Vulnerabilities in Devices via Custom Attack Playbooks
6d ago
·
2 sources
68
Critical RCE Vulnerability in BeyondTrust Software Requires Immediate Patching
Feb 9
·
1495 sources
67
Critical FatFs Vulnerabilities Enable Physical Access Attacks on Millions of Devices
Jul 3
·
11 sources
67
Critical iOS Exploit Threatens Crypto Wallet Security
1d ago
·
4 sources
63
Critical Buffer Overflow Vulnerability in UTT HiPER 1250GW Disclosed
Jul 6
·
2 sources
62
Critical RCE Vulnerabilities in HPE ArubaOS-CX Require Immediate Patching
Sep 4
·
10 sources
61
Apple Releases Critical Security Updates for iOS 27 and macOS 27
6d ago
·
11 sources
61
Multiple Remote Code Execution Vulnerabilities in Oracle Outside In Technology
Sep 9
·
4 sources
61
Apple Accelerates Security Updates Amid AI-Driven Cyber Threats
Jun 29
·
50 sources
61
Rockwell Automation Addresses Critical DoS Vulnerabilities in RSLinx Classic
Sep 2
·
4 sources
61
Rocky Linux 8 and 9 Vulnerabilities Lead to Remote Code Execution Risks
Sep 2
·
15 sources
59
SUSE MozillaFirefox Denial-of-Service Vulnerabilities Addressed
Jun 24
·
9 sources
58
Wireshark 4.6.8 Addresses 28 Security Bugs, Including Critical File Parser Vulnerabilities
Aug 13
·
6 sources
58
AI-Driven WeChat Worm Threatens Over 1 Billion Accounts
Sep 8
·
21 sources
58
Multiple Vulnerabilities Discovered in GNU gawk Software
Jul 14
·
10 sources
58
Multiple CVEs Discovered in Cisco IOS XR Software
Sep 12
·
4 sources
58
Denial-of-Service Vulnerabilities in Rockwell Automation Logix Platforms
Sep 1
·
2 sources
58
Analysis of CVE-2024 Vulnerabilities in Windows Services
Sep 13
·
2 sources
55
OpenAI Launches GPT-5.4-Cyber Amidst Cybersecurity Arms Race
Apr 14
·
1370 sources
52
SUSE and openSUSE BusyBox Vulnerabilities Addressed in Recent Updates
Sep 1
·
4 sources
46
Prev
1 / 9
Next
Related Articles (49)
Hackers Exploit iOS Vulnerabilities to Steal Private Keys
Cryptonews
·
23h ago
Critical Vulnerabilities in HPE Aruba Networking EdgeConnect SD
Ccb.Belgium.Be
·
4d ago
iOS 26.7 arrives as Apple's security-only alternative to iOS 27
Cultofmac
·
5d ago
AI Worms Write Their Own Attack Playbook. Your Devices Are the Target.
Gadgetreview
·
6d ago
Vulnerability-and-Exploit
Sploitus
·
Sep 13
Cp 169 11186 Faaa9 1
www.twcert.org.tw
·
Sep 11
Cybersecurity Advisories
Ncsa.Qa
·
Sep 10
Android's September 2026 Updates Patch 180 Vulnerabilities
Securityweek
·
Sep 9
ZDI-26-638: Oracle Outside In Technology WPS File Parsing Memory Corruption Remote Code Execution Vulnerability
Zerodayinitiative
·
Sep 9
Microsoft shatters Patch Tuesday record with nearly 1,000 fixes released
Thestack.Technology
·
Sep 8
CWE-131: Incorrect Calculation of Buffer Size
cwe.mitre.org
·
Sep 8
This AI-Developed Computer Worm Could Have Hijacked a Billion Accounts
Uk.Pcmag
·
Sep 8
September 2026 security updates
support.sap.com
·
Sep 8
AI created worm could have hacked millions of people in a few hours
Techlicious
·
Sep 8
CVE-2026
Api.Msrc.Microsoft
·
Sep 8
CVE-2026
Api.Msrc.Microsoft
·
Sep 8
Security Bulletin: HPE Aruba Networking AOS-CX
Redlegg
·
Sep 4
CVE-2026-9637
www.rockwellautomation.com
·
Sep 2
Rocky Linux 8 wget Moderate Memory Corruption and Code Exec RLSA-2026
Linuxsecurity
·
Sep 2
openSUSE BusyBox Moderate Buffer Overflow Vulnerability Update 2026-3908
Linuxsecurity
·
Sep 1
Rockwell Automation Logix Platform
Cisa
·
Sep 1
SB2026081987
Cybersecurity-Help.Cz
·
Aug 19
SB2026081825 - Multiple vulnerabilities in macOS Tahoe
Cybersecurity-Help.Cz
·
Aug 18
CVE-2026-19790 - Exploits & Severity
Feedly
·
Aug 14
Wireshark 4.6.8 Released to Patch 28 Security Vulnerabilities
Gbhackers
·
Aug 13
SAP Commerce Cloud flaw opens unauthenticated path to code execution
Pcquest
·
Aug 12
Zoom Patches “Zoomsday” Zero
Securityaffairs.Co
·
Aug 11
Critical SAP Vulnerabilities Let Attackers Inject Malicious Code and Corrupt Memory
Cybersecuritynews
·
Aug 11
Cisco warns of high
Bleepingcomputer
·
Aug 11
190
cwe.mitre.org
·
Aug 10
CC-4824
Digital.Nhs.Uk
·
Aug 6
Research Worth Reading - Week 30, 2026 - PentesterLab's Blog
Pentesterlab
·
Jul 27
Security Advisories
nginx.org
·
Jul 20
CVE-2026-14721 - Exploits & Severity
Feedly
·
Jul 5
Risky Bulletin: FatFs bugs enable physical access attacks on a load of devices
News.Risky.Biz
·
Jul 3
Apple patches urgent security flaws as the threat from artificial intelligence looms: this is the first time
En.Ilsole24Ore
·
Jun 30
Oracle Linux 9 NGINX Critical Arbitrary Code Execution Vuln ELSA-2026
Linuxsecurity
·
Jun 25
SUSE MozillaFirefox Important Fix Denial-of-Service Issue 2026-2582
Linuxsecurity
·
Jun 24
CVE-2026-12806 - Exploits & Severity
Feedly
·
Jun 21
June Patch Tuesday marks a ‘new normal’ with over 200 CVEs, 32 rated ‘critical’
Csoonline
·
Jun 10
How attackers were able to spread spyware through WhatsApp with just a phone call
Adaderana.Lk
·
Jun 10
USN-8156-2: GDK
Ubuntu
·
Jun 9
Cloud Atlas said in a report shared with GBhackers
securelist.ru
·
May 25
How Smartphones Get Hacked: The 2026 Threat Landscape You Need to Understand
Vocal.Media
·
May 20
Linux Kernel bug Fragnesia allows local root access attacks
Securityaffairs.Co
·
May 14
USN-8252-1: OpenJPEG vulnerability
Ubuntu
·
May 7
USN-8251-1: libpng vulnerabilities
Ubuntu
·
May 7
Alert for Major Buffer Overflow Memory Issue in Fedora 43 glibc Update
Linuxsecurity
·
May 3
CVE-2026-6560 - Exploits & Severity
Feedly
·
Apr 19
Prev
1 / 10
Next
Related Entities
Zero-day Exploit
Denial of Service
Malware
Data Breach
DDoS
Worm
Phishing
Sql Injection
Denial-of-Service
Server-Side Request Forgery
Ransomware
Privilege Escalation