Threats Affecting Nepal
View all threats affecting or targeting Nepal. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Affecting Nepal
Click on any threat for detailed analysis and mitigation recommendations
BRUSHWORM and BRUSHLOGGER uncovered 0 A South Asian financial institution was targeted with two custom malware components: BRUSHWORM, a modular backdoor, and BRUSHLOGGER, a keylogger. BRUSHWORM features anti-analysis checks, encrypted configuration, scheduled task persistence, modular payload downloading, USB worm propagation, and extensive file theft. BRUSHLOGGER uses DLL side-loading to capture system-wide keystrokes with window context tracking. The malware's low sophistication and implementation flaws suggest an inexperienced author, possibly using AI code-generation tools. Multiple testing versions were discovered on VirusTotal, indicating iterative development. The malware components combine to create a functional collection platform with modular loading, USB propagation, broad file theft, air-gap bridging, and persistent keystroke capture. Join the discussion | AlienVault OTX General | 03/27/2026, 08:45:50 UTC Added: 03/27/2026, 09:44:44 UTC |
CVE-2024-51225: n/aCVE-2024-51225 0 A stored cross-site scripting (XSS) vulnerability in the component /admin/add-brand.php of Phpgurukul Vehicle Record Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the brandname parameter. Join the discussion | CVE Database V5 | 03/23/2026, 00:00:00 UTC Added: 03/23/2026, 15:45:54 UTC |
CVE-2024-51224: n/aCVE-2024-51224 0 Multiple cross-site scripting (XSS) vulnerabilities in the component /admin/edit-vehicle.php of Phpgurukul Vehicle Record Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the vehiclename, modelnumber, regnumber, vehiclesubtype, chasisnum and enginenumber parameters. Join the discussion | CVE Database V5 | 03/23/2026, 00:00:00 UTC Added: 03/23/2026, 15:45:54 UTC |
CVE-2024-51223: n/aCVE-2024-51223 0 A stored cross-site scripting (XSS) vulnerability in the component /admin/profile.php of Phpgurukul Vehicle Record Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Mobile Number parameter. Join the discussion | CVE Database V5 | 03/23/2026, 00:00:00 UTC Added: 03/23/2026, 15:45:54 UTC |
CVE-2026-3402: Cross Site Scripting in PHPGurukul Student Record Management SystemCVE-2026-3402 0 A security vulnerability has been detected in PHPGurukul Student Record Management System up to 1.0. This vulnerability affects unknown code of the file /edit-course.php. Such manipulation of the argument Course Short Name leads to cross site scripting. The attack can be executed remotely. The exploit has been disclosed publicly and may be used. Join the discussion | CVE Database V5 | 03/02/2026, 00:32:09 UTC Added: 03/02/2026, 00:56:10 UTC |
CVE-2024-30982: n/aCVE-2024-30982 0 SQL Injection vulnerability in phpgurukul Cyber Cafe Management System Using PHP & MySQL 1.0 allows attackers to run arbitrary SQL commands via the upid parameter in the /view-user-detail.php file. Join the discussion | CVE Database V5 | 04/17/2024, 00:00:00 UTC Added: 02/25/2026, 21:46:56 UTC |
CVE-2024-48293: n/aCVE-2024-48293 0 Incorrect access control in QuickHeal Antivirus Pro 24.1.0.182 and earlier allows authenticated attackers with low-level privileges to arbitrarily modify antivirus settings. Join the discussion | CVE Database V5 | 11/18/2024, 00:00:00 UTC Added: 02/25/2026, 21:43:47 UTC |
CVE-2024-48279: n/aCVE-2024-48279 0 A HTML Injection vulnerability was found in /search-result.php of PHPGurukul User Registration & Login and User Management System 3.2. This vulnerability allows remote attackers to execute arbitrary HTML code via the searchkey parameter in a POST HTTP request. Join the discussion | CVE Database V5 | 10/15/2024, 00:00:00 UTC Added: 02/25/2026, 21:43:45 UTC |
CVE-2024-46531: n/aCVE-2024-46531 0 phpgurukul Vehicle Record Management System v1.0 was discovered to contain a SQL injection vulnerability via the searchinputdata parameter at /index.php. Join the discussion | CVE Database V5 | 10/30/2024, 00:00:00 UTC Added: 02/25/2026, 21:43:30 UTC |
CVE-2024-46241: n/aCVE-2024-46241 0 PHPGurukul Dairy Farm Shop Management System v1.1 is vulnerable to Cross-Site Scripting (XSS) via the pname parameter in add_product.php and edit_product.php. Join the discussion | CVE Database V5 | 09/23/2024, 00:00:00 UTC Added: 02/25/2026, 21:43:22 UTC |
Showing 1 to 10 of 83 results