Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
CVE-2026-77146: CWE-862 Missing Authorization in TYPO3 Extension "femanager"CVE-2026-77146 0 The extension's invitation controller fails to stop processing after redirecting on invalid input (missing hash, non-existent, disabled, or deleted users), allowing an unauthenticated attacker to set a new password for and re-enable an arbitrary existing frontend user account. This vulnerability is only present in the 8.x versions of the extension. Join the discussion | CVE Database V5 | 08/25/2026, 09:00:31 UTC Added: 08/25/2026, 09:07:50 UTC |
CVE-2026-77135: CWE-639 Authorization Bypass Through User-Controlled Key in TYPO3 Extension "femanager"CVE-2026-77135 0 The extension's user detail view fails to verify that a requested user record matches the configured or logged-in target, allowing any visitor with access to the Detail or List plugin to retrieve another frontend user's profile data, including name, email, date of birth and address, by supplying an arbitrary user ID. Join the discussion | CVE Database V5 | 08/25/2026, 09:00:40 UTC Added: 08/25/2026, 09:07:48 UTC |
CVE-2026-77134: CWE-863 Incorrect Authorization in TYPO3 Extension "femanager"CVE-2026-77134 0 The extension fails to require the dedicated admin confirmation token when processing an admin-approval request, so a regular user confirmation hash, obtainable by any visitor through the public resend-confirmation action, is sufficient to self-approve a pending account awaiting admin approval. Join the discussion | CVE Database V5 | 08/25/2026, 09:00:40 UTC Added: 08/25/2026, 09:07:48 UTC |
CVE-2026-77133: CWE-862 Missing Authorization in TYPO3 Extension "femanager"CVE-2026-77133 0 The extension fails to restrict which frontend usergroups a logged-in user may assign to their own account when the profile edit plugin uses its default field configuration, allowing self-service privilege escalation into arbitrary frontend groups. Join the discussion | CVE Database V5 | 08/25/2026, 09:00:41 UTC Added: 08/25/2026, 09:07:48 UTC |
Showing 1 to 4 of 4 results