Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
0 ILIAS before 9.24, 10.12, and 11.5 contains an unrestricted file upload vulnerability in QTI question import image handling (ilQtiMatImageSecurity) that allows authenticated authors to write executable files. Attackers with question pool import rights can import a crafted archive writing a .htaccess and PHP file to the web-served image directory, achieving remote code execution as the web server user. Join the discussion | CVE Database V5 | 10/09/2026, 15:04:59 UTC Added: 10/09/2026, 15:34:06 UTC |
0 ILIAS before 9.24, 10.x before 10.12 and 11.x before 11.5 contains an argument injection vulnerability in assImagemapQuestionGUI that allows question authors to inject ImageMagick convert options via uploaded image filenames. Attackers can embed tab-separated options, which escapeshellcmd() does not neutralise, to write a PHP file under the web root and achieve remote code execution. Join the discussion | CVE Database V5 | 10/08/2026, 14:10:35 UTC Added: 10/08/2026, 14:19:19 UTC |
ILIAS versions prior to 9.22, 10.10, and 11.3 contain an unauthenticated PHP object injection vulnerability. This flaw allows attackers to inject serialized objects through the LTI authentication endpoint and trigger deserialization via the Shibboleth back-channel logout endpoint. Exploitation can lead to remote code execution as the web server user by writing attacker-controlled PHP content to a web-accessible path. Join the discussion | CVE Database V5 | 09/11/2026, 00:00:00 UTC Added: 08/26/2026, 15:52:59 UTC |
ILIAS versions before 9.23, 10.11, and 11.4 contain an authorization bypass vulnerability in ilObjGroupGUI where saveMapSettingsObject() and updateGroupTypeObject() perform state-changing operations without write permission checks. Authenticated users with only read access to a group can craft POST requests to modify group map settings and didactic template assignments, changing group modes and permissions for all members. Join the discussion | CVE Database V5 | 09/07/2026, 12:23:54 UTC Added: 09/07/2026, 12:52:46 UTC |
0 ILIAS before versions 9.22, 10.10, and 11.3 contains a SQL injection vulnerability in the repository trash table where the table navigation sort field from HTTP requests is passed directly into the ORDER BY clause of a SQL query without validation against declared sortable columns. Authenticated users with write permission on any container can inject arbitrary SQL through the sort parameter, and because multi-statement execution is enabled in the database layer, stacked queries enable full database read and write access as well as administrator account takeover. Join the discussion | CVE Database V5 | 09/04/2026, 17:37:16 UTC Added: 09/04/2026, 17:52:47 UTC |
0 ILIAS before versions 9.22, 10.10, and 11.3 contains an arbitrary file read vulnerability in the SOAP addFile method that allows authenticated users to read server files by supplying crafted XML with COPY-mode imports. Attackers can construct absolute file paths through an unsandboxed import directory and retrieve sensitive files including configuration files containing database credentials and setup passwords. Join the discussion | CVE Database V5 | 08/31/2026, 10:51:03 UTC Added: 08/31/2026, 11:07:40 UTC |
Showing 1 to 6 of 6 results