Threats Affecting Tunisia
View all threats affecting or targeting Tunisia. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Affecting Tunisia
Click on any threat for detailed analysis and mitigation recommendations
The 13-country effort, named Operation Ramz, targeted cyber threats in the Middle East and North Africa region. The post 201 Arrested in Crackdown on Cybercrime in Middle East, North Africa appeared first on SecurityWeek . Join the discussion | SecurityWeek | 05/19/2026, 10:32:14 UTC Added: 05/19/2026, 10:36:37 UTC |
0 An Incorrect Access Control vulnerability exists in INDEX-EDUCATION PRONOTE prior to 2025.2.8. The affected components (index.js and composeUrlImgPhotoIndividu) allow the construction of direct URLs to user profile images based solely on predictable identifiers such as user IDs and names. Due to missing authorization checks and lack of rate-limiting when generating or accessing these URLs, an unauthenticated or unauthorized actor may retrieve profile pictures of users by crafting requests with guessed or known identifiers. Join the discussion | CVE Database V5 | 03/16/2026, 00:00:00 UTC Added: 03/16/2026, 18:43:23 UTC |
0 The SPIP interface_traduction_objets plugin versions prior to 2.2.2 contain an authenticated remote code execution vulnerability in the translation interface workflow. The plugin incorporates untrusted request data into a hidden form field that is rendered without SPIP output filtering. Because fields prefixed with an underscore bypass protection mechanisms and the hidden content is rendered with filtering disabled, an authenticated attacker with editor-level privileges can inject crafted content that is evaluated through SPIP's template processing chain, resulting in execution of code in the context of the web server. Join the discussion | CVE Database V5 | 02/25/2026, 03:08:11 UTC Added: 02/25/2026, 04:11:31 UTC |
0 The SPIP jeux plugin versions prior to 4.1.1 contain a reflected cross-site scripting (XSS) vulnerability in the pre_propre pipeline. The plugin incorporates untrusted request parameters into HTML output without proper output encoding, allowing attackers to inject arbitrary script content into pages that render a jeux block. When a victim is induced to visit a crafted URL, the injected content is reflected into the response and executed in the victim's browser context. Join the discussion | CVE Database V5 | 02/25/2026, 03:07:57 UTC Added: 02/25/2026, 04:11:32 UTC |
The SPIP interface_traduction_objets plugin versions prior to 2.2.2 contain an authenticated SQL injection vulnerability in interface_traduction_objets_pipelines.php. When handling translation requests, the plugin reads the id_parent parameter from user-supplied input and concatenates it directly into a SQL WHERE clause in a call to sql_getfetsel() without input validation or parameterization. An authenticated attacker with editor-level privileges can inject crafted SQL expressions into the id_parent parameter to manipulate the backend query. Successful exploitation can result in disclosure or modification of database contents and may lead to denial of service depending on the database configuration and privileges. Join the discussion | CVE Database V5 | 02/25/2026, 03:07:44 UTC Added: 02/25/2026, 04:11:32 UTC |
0 The 'Saisies pour formulaire' (Saisies) plugin for SPIP versions 5.4.0 through 5.11.0 contains a critical Remote Code Execution (RCE) vulnerability. An attacker can exploit this vulnerability to execute arbitrary code on the server. Users should immediately update to version 5.11.1 or later. Join the discussion | CVE Database V5 | 02/19/2026, 14:58:15 UTC Added: 02/19/2026, 15:16:03 UTC |
Cybercriminals Abuse Open-Source Tools To Target Africa’s Financial Sector Source: https://unit42.paloaltonetworks.com/cybercriminals-attack-financial-sector-across-africa/ Join the discussion | Reddit InfoSec News | 06/25/2025, 00:21:16 UTC Added: 06/25/2025, 00:34:15 UTC |
TP-Link VN020 F3v(T) TT_V6.2.1021) - DHCP Stack Buffer Overflow Join the discussion | Exploit-DB RSS Feed | 05/13/2025, 00:00:00 UTC Added: 06/10/2025, 21:04:30 UTC |
0 A cross-site scripting (XSS) vulnerability in the Article module of SPIP v4.3.3 allows authenticated attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Title parameter. Join the discussion | CVE Database V5 | 11/26/2024, 00:00:00 UTC Added: 02/25/2026, 21:38:08 UTC |
0 An authenticated arbitrary file upload vulnerability in the Documents module of SPIP v4.3.3 allows attackers to execute arbitrary code via uploading a crafted PDF file. Join the discussion | CVE Database V5 | 11/26/2024, 00:00:00 UTC Added: 02/25/2026, 21:38:08 UTC |
Showing 1 to 10 of 10 results