Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
0 The Vite development server option `server.fs.deny` intended to block access to specified files can be bypassed on case-insensitive filesystems such as Windows by using case-augmented filenames. This allows unauthorized access to files that should be denied, including sensitive configuration and secret files. The issue arises because the underlying glob matching is case-sensitive while the filesystem is not, enabling attackers to circumvent the deny list by altering filename casing. This vulnerability affects Vite versions from 2.7.0 up to but not including 5.0.12. Join the discussion | GCVE Database | 08/13/2026, 17:48:54 UTC Added: 09/29/2026, 04:42:04 UTC |
0 Vite's development server option `server.fs.deny` did not properly deny requests for patterns that include directories, such as `/foo/**/*`. This affected applications that set a custom `server.fs.deny` with directory patterns and exposed the Vite dev server to the network. The issue was due to the use of picomatch with the `matchBase: true` option, which only matches basenames and not full paths, allowing unauthorized access to files under denied directories. This vulnerability is fixed in Vite versions 5.2.6, 5.1.7, 5.0.13, 4.5.3, 3.2.10, and 2.9.18. Join the discussion | GCVE Database | 08/13/2026, 17:48:54 UTC Added: 09/29/2026, 04:42:04 UTC |
A vulnerability in Vite allows bypassing the file system access restrictions when using the '?import&raw' query parameter. This results in the contents of arbitrary files outside the allowed serving list being returned to the browser. The issue affects Vite versions from 2.5.1 up to but not including 5.4.6. A proof of concept demonstrates that files normally blocked by the '@fs' deny list can be accessed by appending '?import&raw' to the URL. The vulnerability has a medium severity with a CVSS score of 5.3. Join the discussion | GCVE Database | 08/13/2026, 17:48:54 UTC Added: 09/29/2026, 04:42:04 UTC |
0 A DOM Clobbering vulnerability (CVE-2024-45812) exists in Vite when building scripts with output formats cjs, iife, or umd. This flaw allows an attacker to manipulate the document.currentScript property via a named HTML element, causing the dynamic import of scripts from attacker-controlled URLs. This can lead to cross-site scripting (XSS) in web pages that include Vite-bundled scripts and allow injection of scriptless attacker-controlled HTML elements. The vulnerability affects Vite versions from 2.5.1 up to but not including 5.4.6. A patch is available to address this issue. Join the discussion | GCVE Database | 08/13/2026, 17:48:54 UTC Added: 09/29/2026, 04:42:04 UTC |
0 Vite development server versions from 2.5.1 up to but not including 6.0.9 have a vulnerability that allows any website to send requests to the dev server and read responses due to permissive default CORS settings and lack of Origin header validation on WebSocket connections. This affects even local-only dev server instances. The vulnerability can lead to unauthorized reading of development server resources via cross-origin requests and WebSocket hijacking. A fix is available in newer versions of Vite. Mitigations include configuring CORS to restrict origins, setting allowed hosts when using reverse proxies or non-localhost domains, and using Chrome 94+ or HTTPS to mitigate Host header validation issues. Join the discussion | GCVE Database | 08/13/2026, 17:48:54 UTC Added: 09/29/2026, 04:42:04 UTC |
A vulnerability in Vite allows bypassing the server.fs.deny restriction when using the ?raw?? or ?import&raw?? query parameters. This enables an attacker to retrieve the contents of arbitrary files outside the allowed serving list. The issue affects Vite dev servers explicitly exposed to the network via the --host option or server.host configuration. The vulnerability arises because trailing question marks are stripped inconsistently, allowing the bypass of query string checks. Join the discussion | GCVE Database | 08/13/2026, 17:48:54 UTC Added: 09/29/2026, 04:42:04 UTC |
0 Vite versions from 2.5.1 up to but not including 6.2.5 contain a vulnerability (CVE-2025-31486) that allows an attacker to bypass the server.fs.deny file access restrictions. This enables the contents of arbitrary files to be returned to the browser when the Vite development server is exposed to the network. The bypass leverages requests ending with .svg combined with certain query parameters or headers, and also relative path traversal before id normalization. The vulnerability requires the file to be smaller than the default 4kB inline asset limit and affects Vite 6.0 and later. A proof of concept demonstrates reading sensitive files like /etc/passwd via crafted requests. A patch is available to fix this issue. Join the discussion | GCVE Database | 08/13/2026, 17:48:54 UTC Added: 09/29/2026, 04:42:02 UTC |
0 Vite versions from 2.5.1 up to but not including 6.2.6 have a vulnerability where the dev server's file system access restrictions can be bypassed using an invalid HTTP request-target containing a '#' character. This allows an attacker to retrieve arbitrary files if the dev server is explicitly exposed to the network and running on Node or Bun runtimes. The issue arises because Vite assumes the request URL will not contain '#', but Node and Bun do not reject such requests internally, enabling the bypass. Deno runtime is not affected due to different URL handling. Join the discussion | GCVE Database | 08/13/2026, 17:48:54 UTC Added: 09/29/2026, 04:42:02 UTC |
Showing 1 to 8 of 8 results