Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
Heym versions before 0.0.106 have a credential exfiltration vulnerability in the POST /api/credentials/test endpoint. This flaw allows collaborators with shared credential access to override the destination URL in the config parameter, causing the server to send decrypted authentication secrets to attacker-controlled endpoints. The vulnerability has a CVSS 3.1 score of 6.5, indicating a high severity impact on confidentiality without affecting integrity or availability. Join the discussion | GCVE Database | 09/27/2026, 03:31:06 UTC Added: 09/27/2026, 04:29:48 UTC |
0 heym versions before 0.0.109 have a server-side request forgery (SSRF) vulnerability in the Slack, Discord, and Crawler workflow nodes. These nodes use user-supplied URLs from credentials without proper validation, allowing registered users to make the backend server send HTTP requests to internal or cloud metadata endpoints and receive the full response. This vulnerability can lead to unauthorized information disclosure. Join the discussion | GCVE Database | 09/27/2026, 03:31:06 UTC Added: 09/27/2026, 04:29:48 UTC |
A vulnerability in heym versions before 0.0.105 allows authenticated users to bypass server-side request forgery (SSRF) protections. This occurs because egress guards are not applied to integration services that use credential-supplied base URLs. Attackers can exploit this by configuring credentials to point to loopback, private, or cloud-metadata addresses, enabling them to read internal service responses as workflow node output. Join the discussion | GCVE Database | 09/27/2026, 03:31:06 UTC Added: 09/27/2026, 04:29:48 UTC |
Heym versions before 0.0.53 contain multiple independent vulnerabilities including unsafe use of Python eval() in workflow conditions, improper webhook signature verification for Slack and Telegram, insecure OAuth redirect URI validation, and plaintext storage of sensitive tokens. These flaws allow arbitrary code execution, unauthorized workflow triggering, cross-site scripting via OAuth, and token theft from database exposure. Join the discussion | GCVE Database | 09/27/2026, 03:31:06 UTC Added: 09/27/2026, 04:29:48 UTC |
heym versions before 0.0.91 have a sandbox escape vulnerability in the expression engine's DotList map/filter and fallback resolver. This flaw allows authenticated users to execute arbitrary Python code by exploiting dunder attribute access to invoke os.system, leading to command execution as the backend process. Join the discussion | GCVE Database | 09/27/2026, 03:31:06 UTC Added: 09/27/2026, 04:29:48 UTC |
Heym versions 0.0.90 and earlier have two server-side request forgery (SSRF) vulnerabilities related to improper egress filtering. These issues allow an attacker controlling image URLs to cause the server to make unauthorized requests to internal or cloud metadata endpoints. The vulnerabilities are fixed in version 0.0.91 by improving URL validation and IP address checks. Join the discussion | GCVE Database | 09/27/2026, 03:31:06 UTC Added: 09/27/2026, 04:29:48 UTC |
0 heym versions before 0.0.105 contain a vulnerability in the Redis workflow node where the system does not properly handle failed credential authorization lookups. Instead of rejecting unauthorized or non-existent credentials, the node falls back to connecting to localhost Redis with no password, potentially allowing unauthorized access to the local Redis instance. The impact varies by deployment; if no Redis is running locally, this results in a connection error rather than data exposure. Join the discussion | GCVE Database | 09/27/2026, 03:31:06 UTC Added: 09/27/2026, 04:29:48 UTC |
0 heym workflow automation platform versions prior to 0.0.91 store and return multiple sensitive capability secrets in plaintext. These secrets include webhook header-auth values, MCP API keys, portal session tokens, workflow execution JWTs, Discord interaction tokens, and global variables. The plaintext secrets are accessible via API responses, stored unsanitized in execution history, and can leak through logs and proxies. Users with read access to workflows, team members, or anyone with access to backups or logs can retrieve and misuse these secrets to execute workflows or impersonate secret owners. Join the discussion | GCVE Database | 09/27/2026, 03:31:06 UTC Added: 09/27/2026, 04:29:48 UTC |
AzuraCast versions prior to 0.23.4 have a code injection vulnerability in the ConfigWriter::cleanUpString() method. This flaw allows authenticated users with Media or Profile permissions to inject arbitrary Liquidsoap code via unsanitized string interpolation sequences. Exploitation can lead to execution of shell commands as the azuracast user when the station restarts. Join the discussion | GCVE Database | 09/27/2026, 03:31:05 UTC Added: 09/27/2026, 04:29:51 UTC |
AzuraCast versions before 0.23.8 have a broken access control vulnerability in the GET /api/station/{id}/vue/profile endpoint. This flaw allows authenticated users with only View Station Page permission to access Icecast/Shoutcast admin, source, and relay passwords in plaintext. Attackers can use the exposed admin password to authenticate to the Icecast admin interface without needing Broadcasting permission. Join the discussion | GCVE Database | 09/27/2026, 03:31:05 UTC Added: 09/27/2026, 04:29:51 UTC |
Showing 1 to 10 of 139632 results