Skip to content
Signals
NVD · CVE-2026-18907 · Path Traversal in Download File Feature in com.talpa.hibrowser 2.23.1.1 on Android allows arbitrary file write via directory traversal sequences in the filenameNVD · CVE-2026-18897 · 8.8 · A vulnerability was identified in UTT HiPER 1250GW up to v3.2.7-210907-180535. The impacted element is the function strcpy of the file /goform/getOneApConfTempENVD · CVE-2026-18896 · 6.3 · A vulnerability was determined in lavkush-maurya Student-Registration-System 1.0. The affected element is an unknown function of the file /student/changepass.phNVD · CVE-2026-18895 · 8.8 · A vulnerability was found in UTT HiPER 1250GW up to 3.2.7-210907-180535. Impacted is the function strcpy of the file /goform/APSecurity_5g. Performing a manipulCISA KEV · CVE-2026-18556 · 7.4 · N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability · Added 2026-08-04 · Due 2026-08-07CISA KEV · CVE-2026-34486 · 7.5 · Apache Tomcat Missing Encryption of Sensitive Data Vulnerability · Added 2026-08-04 · Due 2026-08-07NVD · CVE-2026-18907 · Path Traversal in Download File Feature in com.talpa.hibrowser 2.23.1.1 on Android allows arbitrary file write via directory traversal sequences in the filenameNVD · CVE-2026-18897 · 8.8 · A vulnerability was identified in UTT HiPER 1250GW up to v3.2.7-210907-180535. The impacted element is the function strcpy of the file /goform/getOneApConfTempENVD · CVE-2026-18896 · 6.3 · A vulnerability was determined in lavkush-maurya Student-Registration-System 1.0. The affected element is an unknown function of the file /student/changepass.phNVD · CVE-2026-18895 · 8.8 · A vulnerability was found in UTT HiPER 1250GW up to 3.2.7-210907-180535. Impacted is the function strcpy of the file /goform/APSecurity_5g. Performing a manipulCISA KEV · CVE-2026-18556 · 7.4 · N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability · Added 2026-08-04 · Due 2026-08-07CISA KEV · CVE-2026-34486 · 7.5 · Apache Tomcat Missing Encryption of Sensitive Data Vulnerability · Added 2026-08-04 · Due 2026-08-07

IOC

IOC API

Retrieve indicators of compromise with type, TLP, confidence and status filters. All values use RFC 5737 documentation ranges — no real malicious infrastructure.

Safety level: Restricted. All responses are editorially reviewed, redacted and safe for enterprise consumption. No raw IOC data, dark web content, exploit code or stolen credentials.

Example use cases

  • SIEM enrichment and correlation rules
  • Automated blocking list updates
  • Threat hunting indicator feeds
  • Incident response triage support

Endpoints

IOC Response

Indicator of compromise with type, confidence, TLP classification and defensive context.

id*

IOC identifier

string

type*

Indicator type: ip, domain, url, hash, email

string

value*redacted

Indicator value (RFC 5737 ranges for IPs)

string

confidence*

Confidence level: low, medium, high

string

tlp*

TLP classification: clear, green, amber, red

string

firstSeen*

ISO 8601 first observation date

string

defensiveGuidance

Recommended defensive action

string
{ "id": "ioc-001", "type": "ip", "value": "[REDACTED] 192.0.2.••", "confidence": "high", "tlp": "green", "firstSeen": "2026-04-15", "defensiveGuidance": "Block at perimeter firewall" }

Safety notes

All IP addresses use RFC 5737 documentation ranges (192.0.2.0/24, 198.51.100.0/24, 203.0.113.0/24).

No real malicious infrastructure, C2 addresses or active threat indicators.

Hash values are synthetic — not real malware samples.

IOC API — Enterprise API | Dragons Community