Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
0 9Router is an AI router & token saver. Prior to 0.5.6, 9Router deployments that allow requests to reach Next.js without the sanitizing custom-server.js wrapper use the client-supplied X-9r-Real-Ip value as the bucket key in getClientIp, checkLock, and recordFail in src/lib/auth/loginLimiter.js for POST /api/auth/login. A remote unauthenticated attacker can rotate the header on every password guess so each request uses a new failed-attempt bucket and the five-attempt progressive lockout never returns HTTP 429. This permits unthrottled password guessing against the dashboard login and can lead to an administrative session if the password is recovered. This issue is fixed in version 0.5.6. Join the discussion | CVE Database V5 | 09/22/2026, 16:09:07 UTC Added: 09/22/2026, 16:33:28 UTC |
0 9Router is an AI router & token saver. Prior to 0.5.6, 9Router deployments that allow requests to reach Next.js without the sanitizing custom-server.js wrapper trust the client-supplied X-9r-Real-Ip header in src/dashboardGuard.js when isLocalRequest decides whether canAccessPublicLlmApi may skip API-key validation for /api/v1/* routes. A remote unauthenticated attacker can set X-9r-Real-Ip to 127.0.0.1 and be classified as a local client, including on the verified GET /api/v1/models route. This permits unauthorized use of the instance owner's configured LLM providers, consumption of paid credits, and enumeration of configured providers and models. This issue is fixed in version 0.5.6. Join the discussion | CVE Database V5 | 09/22/2026, 16:02:25 UTC Added: 09/22/2026, 16:03:17 UTC |
0 CVE-2026-56677 is a high-severity vulnerability in decolua 9router versions 0.5.4 and earlier. It involves a missing authentication check on the POST /api/auth/oidc/test endpoint, which allows unauthenticated attackers to scan internal services and retrieve OpenID Connect discovery information when dashboard login is disabled. Join the discussion | CVE Database V5 | 08/17/2026, 21:14:06 UTC Added: 08/17/2026, 21:26:43 UTC |
9Router versions prior to 0.4.72 contain a server-side request forgery (SSRF) vulnerability in the /v1/web/fetch endpoint. This endpoint accepts a user-controlled URL parameter that is only syntactically validated without blocking private IP ranges or internal hostnames. An authenticated or locally connected user can exploit this to make the server fetch arbitrary internal URLs, potentially exposing cloud metadata credentials and internal services. The vulnerability has a high severity with a CVSS score of 8.3. Join the discussion | CVE Database V5 | 07/23/2026, 21:16:45 UTC Added: 07/23/2026, 21:37:50 UTC |
0 9Router versions prior to 0.5.2 contain an OS command injection vulnerability that allows a remote authenticated attacker to execute arbitrary code on the host system. This is achieved by bypassing localhost-only route restrictions via the Host header and passing unvalidated arguments to child_process.spawn() through the /api/mcp//sse endpoint. The vulnerability is fixed in version 0.5.2. Join the discussion | CVE Database V5 | 07/15/2026, 20:53:18 UTC Added: 07/15/2026, 21:03:21 UTC |
CVE-2026-56678 is an improper input validation vulnerability in decolua 9router versions prior to 0.5.6. The issue occurs in the Kiro API-key validation endpoint, where a user-controlled region value is used to build an upstream URL. An authenticated attacker can supply a crafted region value to redirect the validation request to an attacker-controlled host, leaking the Kiro API key in the Authorization header. This vulnerability is fixed in version 0.5.6. Join the discussion | CVE Database V5 | 07/15/2026, 20:51:33 UTC Added: 07/15/2026, 21:03:18 UTC |
0 CVE-2026-56679 affects decolua 9router versions prior to 0.5.4. The vulnerability allows an authenticated user to modify security-critical settings via the PATCH /api/settings endpoint because the request body is written to persistent settings without a field whitelist. This can disable authentication for the entire application, exposing protected routes to unauthenticated access. The issue is fixed in version 0.5.4. Join the discussion | CVE Database V5 | 07/15/2026, 20:50:30 UTC Added: 07/15/2026, 21:03:18 UTC |
0 9Router versions from 0.4.30 up to but not including 0.4.37 contain an OS command injection vulnerability in the src/proxy.js middleware. This flaw allows unauthenticated attackers to register custom plugins and execute commands via the MCP bridge due to insufficient protection of certain API endpoints. The vulnerability is fixed starting with version 0.4.37. Join the discussion | CVE Database V5 | 07/15/2026, 20:41:06 UTC Added: 07/15/2026, 21:03:18 UTC |
0 9Router through version 0.4.41 contain an unauthenticated information disclosure vulnerability that allows remote attackers to access sensitive user data by sending requests to unprotected API endpoints. Attackers can enumerate paginated request logs and retrieve complete AI conversation histories including system prompts, user messages, assistant responses, tool calls, and user email addresses by querying the request-logs and request-details API routes which lack authentication middleware. Join the discussion | CVE Database V5 | 07/13/2026, 21:37:52 UTC Added: 07/13/2026, 21:48:07 UTC |
9Router through version 0.4.41 contains an unauthenticated information disclosure vulnerability that allows remote attackers to retrieve plaintext API keys for all connected AI provider accounts by sending a single unauthenticated request to the /api/usage/stats endpoint. Attackers can exploit the missing authentication middleware on the Next.js API route to obtain full API key strings alongside token counts, cost breakdowns, and request metadata, enabling unauthorized use of connected AI provider accounts, billing fraud, and quota exhaustion. Join the discussion | CVE Database V5 | 07/13/2026, 21:37:51 UTC Added: 07/13/2026, 21:48:07 UTC |
Showing 1 to 10 of 18 results