Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
0 Bludit CMS versions up to 3.22.0 and 4.0.0-beta-1 contain an authorization bypass vulnerability. Authenticated users with the Author role can enumerate and delete media files belonging to other users, including administrators, by exploiting unprotected AJAX endpoints. This bypasses the intended IMAGE_RESTRICT isolation control, allowing unauthorized access and deletion of media files across user pages. Join the discussion | CVE Database V5 | 09/25/2026, 17:00:44 UTC Added: 09/25/2026, 17:33:34 UTC |
0 Bludit CMS versions up to 3.22.0 and 4.0.0-beta-1 contain a missing authorization vulnerability that allows authenticated users with Author or Editor roles to access private drafts and scheduled posts of any user, including administrators. This occurs via the content-get-list AJAX endpoint, which does not enforce ownership constraints when the draft parameter is set to true. The vulnerability exposes pre-publication content and sensitive notes site-wide. Join the discussion | CVE Database V5 | 09/25/2026, 16:58:40 UTC Added: 09/25/2026, 17:33:34 UTC |
0 Bludit CMS through 3.22.0 contains a mass assignment vulnerability that allows authenticated users with the Author role to modify privileged page fields reserved for administrators by injecting reserved parameters into a content save request. Attackers can submit reserved fields such as type and username through the Pages::edit() function in bl-kernel/pages.class.php, which iterates all fields declared in dbFields without per-field authorization, enabling an Author to convert pages to static site-wide navigation entries or transfer page ownership to arbitrary accounts. Join the discussion | CVE Database V5 | 09/25/2026, 16:57:38 UTC Added: 09/25/2026, 17:33:34 UTC |
Showing 1 to 3 of 3 results