Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
A missing authorization vulnerability in the TYPO3 extension "femanager" allows logged-in users to escalate their privileges by assigning themselves to arbitrary frontend user groups when using the default profile edit plugin configuration. This affects multiple versions of the extension prior to specific fixed releases. The vulnerability has a medium severity rating with a CVSS score of 6.0. Join the discussion | CVE Database V5 | 08/25/2026, 09:00:41 UTC Added: 08/25/2026, 09:07:48 UTC |
CVE-2026-77134 is a high-severity authorization vulnerability in the TYPO3 extension "femanager." The flaw allows a regular user to self-approve a pending account that requires admin approval by using a user confirmation hash obtainable through a public action, bypassing the intended admin confirmation token requirement. Join the discussion | CVE Database V5 | 08/25/2026, 09:00:40 UTC Added: 08/25/2026, 09:07:48 UTC |
0 CVE-2026-77135 is a high-severity authorization bypass vulnerability in the TYPO3 extension "femanager." It allows any visitor with access to the Detail or List plugin to retrieve another frontend user's profile data by supplying an arbitrary user ID. The vulnerability arises because the extension's user detail view does not verify that the requested user record matches the configured or logged-in target. This can expose sensitive personal information such as name, email, date of birth, and address. Join the discussion | CVE Database V5 | 08/25/2026, 09:00:40 UTC Added: 08/25/2026, 09:07:48 UTC |
CVE-2026-77146 is a high-severity vulnerability in the TYPO3 extension "femanager" version 8.x. The invitation controller in this extension does not properly stop processing after redirecting on invalid input, such as missing hashes or disabled users. This flaw allows an unauthenticated attacker to reset the password and re-enable arbitrary existing frontend user accounts. Join the discussion | CVE Database V5 | 08/25/2026, 09:00:31 UTC Added: 08/25/2026, 09:07:50 UTC |
Showing 1 to 4 of 4 results