Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
0 Craft CMS 5.10.13.2 contains an authenticated remote code execution vulnerability in the Control Panel action app/render-components. Any authenticated user with basic Control Panel access can submit request-controlled component classes and property overrides. By first overriding an EntryType object’s uiLabelFormat and then rendering an Entry that resolves the same request-cached entry type, an attacker can cause arbitrary Twig supplied in the request to be evaluated by renderObjectTemplate(). This render path is not sandboxed. A Twig string callable can therefore reach PHP functions such as system(), resulting in operating-system command execution with the privileges of the PHP/web-server process. The issue was reproduced with an active non-admin Craft Team user with no optional permissions enabled. No access to entry-editing, Settings, utility, user-management, project-config, filesystem, Kubernetes, or environment variables was required. Join the discussion | CVE Database V5 | 10/06/2026, 10:23:25 UTC Added: 10/06/2026, 10:33:54 UTC |
A cross-site scripting (XSS) vulnerability exists in Joomla! CMS versions 4.0.0 through 5.4.8 and 6.0.0 through 6.1.3. The issue arises from improper escaping in the generic audio and video output layouts, allowing injection of malicious scripts during web page generation. Join the discussion | CVE Database V5 | 09/29/2026, 18:31:52 UTC Added: 09/29/2026, 17:09:18 UTC |
0 CVE-2026-79987 is a high-severity vulnerability in Craft CMS that allows a remote, authenticated user with only the accessCp permission (non-admin) to execute operating system commands as the PHP web worker. This issue arises from unsafe reflection due to externally controlled input used to select classes or code. The vulnerability affects Craft CMS versions from 5.8.0 up to but not including 5.10.13. Join the discussion | CVE Database V5 | 09/10/2026, 16:05:55 UTC Added: 09/10/2026, 16:37:36 UTC |
0 Craft CMS versions before 5.10.12 contain a remote code execution vulnerability in the element-index endpoint that allows authenticated content editors to instantiate arbitrary classes through the criteria parameter. Attackers can inject a malicious class via criteria[withTransforms][0][class] that reaches ImageTransforms::normalizeTransform(), then use a PHP gadget chain with yii\rbac\PhpManager to execute code by pointing itemFile to a request log containing PHP payload in the User-Agent header. Join the discussion | CVE Database V5 | 09/08/2026, 15:14:02 UTC Added: 09/08/2026, 15:29:03 UTC |
0 Craft CMS GraphQL entry mutation resolvers (saveEntry, deleteEntry) read siteIddirectly from$argumentswithout passing throughArgumentManagerprepareArguments(), which is the function that enforces site-scope filtering via array_intersect against the GraphQL schema’s allowed sites. The query path (ElementResolverprepareElementQuery) correctly calls prepareArguments()`, so queries to unauthorized sites return empty. But mutations bypass this entirely — an attacker with a token scoped to Site A can create, modify, or delete entries in Site B by passing siteId in the mutations argument. Join the discussion | CVE Database V5 | 09/02/2026, 14:25:15 UTC Added: 09/02/2026, 14:37:50 UTC |
0 Craft CMS GraphQL entry mutation resolvers (saveEntry, deleteEntry) read siteIddirectly from$argumentswithout passing throughArgumentManagerprepareArguments(), which is the function that enforces site-scope filtering via array_intersect against the GraphQL schema’s allowed sites. The query path (ElementResolverprepareElementQuery) correctly calls prepareArguments()`, so queries to unauthorized sites return empty. But mutations bypass this entirely — an attacker with a token scoped to Site A can create, modify, or delete entries in Site B by passing siteId in the mutations argument. Join the discussion | CVE Database V5 | 09/02/2026, 14:19:54 UTC Added: 09/02/2026, 14:22:50 UTC |
The vulnerability allows any authenticated user to change their own password without providing the current password or having an active elevated session. It also allows the attacker to change other users’ passwords if the attacker’s account has Edit users permission (which doesn’t allow changing others’ passwords) and lacks Administrate users permission (which is required to change others’ passwords). Join the discussion | CVE Database V5 | 09/02/2026, 14:11:02 UTC Added: 09/02/2026, 14:22:48 UTC |
CVE-2026-79988 is a high-severity vulnerability in Craft CMS where the Twig sandbox mechanism is improperly configured, allowing dangerous Yii framework functionality. This misconfiguration enables authenticated remote code execution (RCE) similar to previously known issues. The affected versions include 4.0.0-RC1 and 5.0.0-RC1. No official patch or remediation guidance is currently available, and no known exploits are reported in the wild. Join the discussion | CVE Database V5 | 08/27/2026, 15:36:18 UTC Added: 08/27/2026, 16:54:07 UTC |
0 Craft CMS versions from 4.0.0-RC1 before 4.18.2 and from 5.0.0-RC1 before 5.10.6 contain an authenticated remote code execution vulnerability in the control panel element-search condition handling. The vulnerability arises due to a JSON cleanse bypass in condition.config, allowing Yii behavior/event configuration keys to be interpreted after decoding, which enables command execution as the PHP/web user. Join the discussion | CVE Database V5 | 08/24/2026, 15:36:07 UTC Added: 08/24/2026, 15:52:54 UTC |
0 Craft CMS versions before 5.10.8 contain an authentication bypass vulnerability in the elements/save action that allows authenticated users to change passwords without verification. Attackers with edit users permission can reset any user's password including administrators by exploiting the unprotected newPassword field in the User element save flow. Join the discussion | CVE Database V5 | 08/12/2026, 19:07:35 UTC Added: 08/12/2026, 19:27:03 UTC |
Showing 1 to 10 of 29 results