Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
0 MoguBlog versions up to and including 6.2 have an authorization bypass vulnerability in the POST /pictureSort/getPictureSortByUid endpoint. This endpoint lacks the required @AuthorityVerify annotation to enforce role-based permissions, allowing authenticated back-office users without proper image-category permissions to access restricted image-category metadata. Join the discussion | CVE Database V5 | 09/11/2026, 15:25:19 UTC Added: 09/11/2026, 15:33:04 UTC |
MoguBlog through 6.2 fails to validate the comment author identity in the POST /web/comment/add endpoint, allowing authenticated users to post comments attributed to any other user. Attackers can supply arbitrary userUid values in the request body to impersonate other accounts including administrators. Join the discussion | CVE Database V5 | 09/11/2026, 15:25:18 UTC Added: 09/11/2026, 15:33:04 UTC |
MoguBlog versions up to and including 6.2 contain a vulnerability where the /web/comment/closeEmailNotification endpoint does not require authentication. This allows unauthenticated attackers to disable email notifications for any user by modifying the startEmailNotification flag in Redis cache. The vulnerability has a medium severity with a CVSS score of 5.3. Join the discussion | CVE Database V5 | 09/11/2026, 15:25:17 UTC Added: 09/11/2026, 15:33:04 UTC |
MoguBlog through 6.2 contains an authorization bypass vulnerability in the comment deletion endpoint that performs ownership checks against request-body fields instead of the authenticated principal. Attackers can delete arbitrary comments and their replies by supplying comment UIDs and author UIDs obtained from unauthenticated listing endpoints. Join the discussion | CVE Database V5 | 09/11/2026, 15:25:17 UTC Added: 09/11/2026, 15:33:04 UTC |
MoguBlog versions up to and including 6.2 have a vulnerability where the mogu_search service exposes Elasticsearch index management endpoints without authentication. This allows remote attackers to manipulate the blog's search index by deleting, recreating, or injecting entries, potentially disrupting search functionality. Join the discussion | CVE Database V5 | 09/11/2026, 15:25:16 UTC Added: 09/11/2026, 15:33:04 UTC |
0 MoguBlog versions up to and including 6.2 contain an XML external entity (XXE) injection vulnerability in the WeChat callback handler. The vulnerability arises because the application uses an unhardened dom4j SAXReader without restrictions on DTD or external entities, allowing unauthenticated attackers to submit crafted XML with DOCTYPE declarations. This can lead to reading arbitrary local files or triggering outbound HTTP requests, with the results reflected in error responses. Join the discussion | CVE Database V5 | 09/11/2026, 15:25:15 UTC Added: 09/11/2026, 15:33:04 UTC |
Showing 1 to 6 of 6 results