Skip to main content

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Package: pkg:generic/boost

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

Heym versions before 0.0.106 have a credential exfiltration vulnerability in the POST /api/credentials/test endpoint. This flaw allows collaborators with shared credential access to override the destination URL in the config parameter, causing the server to send decrypted authentication secrets to attacker-controlled endpoints. The vulnerability has a CVSS 3.1 score of 6.5, indicating a high severity impact on confidentiality without affecting integrity or availability.

Join the discussion

heym versions before 0.0.109 have a server-side request forgery (SSRF) vulnerability in the Slack, Discord, and Crawler workflow nodes. These nodes use user-supplied URLs from credentials without proper validation, allowing registered users to make the backend server send HTTP requests to internal or cloud metadata endpoints and receive the full response. This vulnerability can lead to unauthorized information disclosure.

Join the discussion

A vulnerability in heym versions before 0.0.105 allows authenticated users to bypass server-side request forgery (SSRF) protections. This occurs because egress guards are not applied to integration services that use credential-supplied base URLs. Attackers can exploit this by configuring credentials to point to loopback, private, or cloud-metadata addresses, enabling them to read internal service responses as workflow node output.

Join the discussion

Heym versions before 0.0.53 contain multiple independent vulnerabilities including unsafe use of Python eval() in workflow conditions, improper webhook signature verification for Slack and Telegram, insecure OAuth redirect URI validation, and plaintext storage of sensitive tokens. These flaws allow arbitrary code execution, unauthorized workflow triggering, cross-site scripting via OAuth, and token theft from database exposure.

Join the discussion

heym versions before 0.0.91 have a sandbox escape vulnerability in the expression engine's DotList map/filter and fallback resolver. This flaw allows authenticated users to execute arbitrary Python code by exploiting dunder attribute access to invoke os.system, leading to command execution as the backend process.

Join the discussion

Heym versions 0.0.90 and earlier have two server-side request forgery (SSRF) vulnerabilities related to improper egress filtering. These issues allow an attacker controlling image URLs to cause the server to make unauthorized requests to internal or cloud metadata endpoints. The vulnerabilities are fixed in version 0.0.91 by improving URL validation and IP address checks.

Join the discussion

heym versions before 0.0.105 contain a vulnerability in the Redis workflow node where the system does not properly handle failed credential authorization lookups. Instead of rejecting unauthorized or non-existent credentials, the node falls back to connecting to localhost Redis with no password, potentially allowing unauthorized access to the local Redis instance. The impact varies by deployment; if no Redis is running locally, this results in a connection error rather than data exposure.

Join the discussion

heym workflow automation platform versions prior to 0.0.91 store and return multiple sensitive capability secrets in plaintext. These secrets include webhook header-auth values, MCP API keys, portal session tokens, workflow execution JWTs, Discord interaction tokens, and global variables. The plaintext secrets are accessible via API responses, stored unsanitized in execution history, and can leak through logs and proxies. Users with read access to workflows, team members, or anyone with access to backups or logs can retrieve and misuse these secrets to execute workflows or impersonate secret owners.

Join the discussion

AzuraCast versions prior to 0.23.4 have a code injection vulnerability in the ConfigWriter::cleanUpString() method. This flaw allows authenticated users with Media or Profile permissions to inject arbitrary Liquidsoap code via unsanitized string interpolation sequences. Exploitation can lead to execution of shell commands as the azuracast user when the station restarts.

Join the discussion

AzuraCast versions before 0.23.8 have a broken access control vulnerability in the GET /api/station/{id}/vue/profile endpoint. This flaw allows authenticated users with only View Station Page permission to access Icecast/Shoutcast admin, source, and relay passwords in plaintext. Attackers can use the exposed admin password to authenticate to the Icecast admin interface without needing Broadcasting permission.

Join the discussion

Showing 1 to 10 of 139632 results

Filters:Package: pkg:generic/boost
Page 1 of 13964
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses