Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
0 CVE-2026-108705 is a missing authorization vulnerability in CordysCRM versions up to 1.9.3. It affects the POST /custom-form/data/import endpoint, allowing authenticated low-privileged users to import data into any custom form by specifying the customFormId. Attackers can upload Excel files with importType ADD or UPDATE to create or overwrite records in custom forms they should not have access to. Join the discussion | CVE Database V5 | 10/11/2026, 01:12:30 UTC Added: 10/11/2026, 01:49:26 UTC |
0 CordysCRM versions up to 1.9.3 contain an authorization bypass vulnerability that allows low-privileged authenticated users to bypass permission checks by manipulating the owner field. This enables attackers to add follow-up records and overwrite certain fields on customer, clue, or opportunity records. Join the discussion | CVE Database V5 | 10/11/2026, 01:12:29 UTC Added: 10/11/2026, 01:49:26 UTC |
0 CordysCRM versions up to 1.9.3 have a missing authorization vulnerability in the POST /approval-resource/push endpoint. This flaw allows authenticated users with low privileges to submit any resource for approval without verifying ownership. Attackers can manipulate approval statuses and read approval details of contracts, invoices, quotations, or orders by supplying arbitrary resourceId values. Join the discussion | CVE Database V5 | 10/11/2026, 01:12:29 UTC Added: 10/11/2026, 01:49:26 UTC |
0 CVE-2026-108702 is a medium severity vulnerability in 1Panel-dev CordysCRM versions up to 1.9.3. It involves a missing authorization check on the POST /approval-flow/webhook/test endpoint, allowing any authenticated user to trigger server-side requests to attacker-controlled URLs. This can be exploited to bypass SSRF protections and probe internal network addresses. Join the discussion | CVE Database V5 | 10/11/2026, 01:12:28 UTC Added: 10/11/2026, 01:49:24 UTC |
0 CVE-2026-108701 is a missing authorization vulnerability in 1Panel-dev CordysCRM versions before 1.9.2. The flaw exists in the ContractController sortModule handler for the POST /contract/sort endpoint, which lacks permission checks. Authenticated users without contract update permissions can modify any contract, including those belonging to other organizations. Join the discussion | CVE Database V5 | 10/11/2026, 01:12:27 UTC Added: 10/11/2026, 01:49:24 UTC |
0 CVE-2026-108700 is a missing authorization vulnerability in 1Panel-dev CordysCRM versions before 1.9.2. Authenticated users without the CONTRACT_BUSINESS_TITLE_READ permission can call a specific API endpoint to list business titles and retrieve sensitive organization invoicing data, including tax IDs, bank account details, and contact information. Join the discussion | CVE Database V5 | 10/11/2026, 01:12:27 UTC Added: 10/11/2026, 01:49:24 UTC |
0 CVE-2026-108692 is a missing authorization vulnerability in 1Panel-dev CordysCRM versions 1.9.0 up to but not including 1.9.2. It affects eight ModuleFieldController endpoints related to data-source fields, which lack proper permission checks. Authenticated users without module permissions can access organization-wide data including leads, contacts, quotations, contracts, payment plans, payment records, orders, and invoices owned by other users. Join the discussion | CVE Database V5 | 10/11/2026, 01:12:26 UTC Added: 10/11/2026, 01:49:24 UTC |
0 CordysCRM is an open source AI-powered customer relationship management system that supports private deployment. From 1.7.0 until 1.7.4, POST /account-pool/page allows an authenticated caller with MODULE_SETTING_UPDATE to place an arbitrary database function in SortRequest.name because CustomerPoolController.page omits Spring request validation, SortRequest.getName relies on an incomplete blacklist, and the CommonMapper.xml sort fragment inserts ${sortName} into an ORDER BY clause. Functions such as extractvalue and updatexml bypass the blacklist and can expose database values through an error oracle when the query returns at least one row. This issue is fixed in version 1.7.4. Join the discussion | CVE Database V5 | 09/18/2026, 19:58:47 UTC Added: 09/18/2026, 20:17:05 UTC |
0 CordysCRM is an open source AI-powered customer relationship management system that supports private deployment. Prior to 1.7.4, ShiroFilter configures /attachment/preview/{id} and /pic/preview/{id} as anonymous, and both routes call AttachmentService.getResource, which performs a bare primary-key lookup without ownership, organization, or permission checks. An unauthenticated caller who guesses or observes an id generated by IDGenerator.nextStr can download files uploaded by users in other organizations because the stored organization id is used only to locate the file rather than authorize the caller. This issue is fixed in version 1.7.4. Join the discussion | CVE Database V5 | 09/18/2026, 19:57:50 UTC Added: 09/18/2026, 20:17:05 UTC |
CordysCRM is an open source AI-powered customer relationship management system that supports private deployment. In version 1.7.3, ApprovalResourceService.sendWebHook reads WebHookConfig.webHookUrl from stored approval-node configuration and passes it through ApprovalFlowService.updateApprovalPostField to HttpClientUtils without the SSRF validation used by the optional testConnect path. A user with PROCESS_SETTING_ADD can configure an internal URL through POST /approval-flow/add and cause the server to request it when POST /approval-action/approve executes the approval action, enabling cloud metadata access, internal network reconnaissance, and interaction with reachable internal services. This issue is fixed in version 1.7.4. Join the discussion | CVE Database V5 | 09/18/2026, 19:56:53 UTC Added: 09/18/2026, 20:02:09 UTC |
Showing 1 to 10 of 19 results