Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
0 Cross-Site Request Forgery (CSRF) in the OrderConfirmController at GET /order/confirm/{order_number} in Roskus Prospero Flow CRM before 5.15.11 allows an unauthenticated attacker to confirm any order on behalf of an authenticated user by directing them to a crafted page. Laravel's VerifyCsrfToken middleware enforces CSRF tokens only on POST, PUT, PATCH, and DELETE requests; the Route::get declaration leaves this state-changing action unprotected. Session cookies configured with SameSite=Lax are automatically included in top-level cross-site navigation, so a single link click triggers OrderConfirmController::confirm() and transitions the target order from pending to confirmed without user authorization. Because order numbers are sequential integers, an attacker can enumerate and confirm all existing orders in a single automated sweep. Join the discussion | CVE Database V5 | 09/04/2026, 15:33:44 UTC Added: 09/04/2026, 15:53:00 UTC |
0 CVE-2026-81931 is a medium severity vulnerability in Roskus Prospero Flow CRM versions prior to 5.16.0. It allows an authenticated user with create product permission to upload files with dangerous types, leading to stored cross-site scripting (XSS) via arbitrary JavaScript execution. The vulnerability arises because the product photo upload feature validates files only by magic bytes and rejects a fixed list of PHP extensions, but uses the client-supplied file extension when storing the file in the public web root. This enables an attacker to upload a file that starts with an image header but has an HTML extension, which is served as text/html and executes script in the application origin. Join the discussion | CVE Database V5 | 08/27/2026, 19:33:27 UTC Added: 08/27/2026, 20:24:33 UTC |
0 CVE-2026-78365 is a critical authorization bypass vulnerability in Roskus Prospero Flow CRM versions 4.0.0 through 5.3.1. It allows any authenticated user to read and modify supplier records belonging to other companies and reassign those records to their own company by manipulating the company_id field in a PUT request to the supplier API endpoint. Join the discussion | CVE Database V5 | 08/24/2026, 12:49:36 UTC Added: 08/24/2026, 13:07:54 UTC |
0 CVE-2026-78337 is a vulnerability in Roskus Prospero Flow CRM before version 5.15.13 that allows authenticated users with create and update company permissions to upload SVG files containing embedded scripts. This can lead to arbitrary JavaScript execution within the application origin. Join the discussion | CVE Database V5 | 08/24/2026, 11:01:30 UTC Added: 08/24/2026, 12:07:57 UTC |
0 CVE-2026-77780 is an authorization bypass vulnerability in Roskus Prospero Flow CRM versions 4.9.1 through before 5.14.2. It allows a user with transaction and accounting creation permissions to access sensitive bank account information of other companies by supplying a bank_account_id or bank_card_id in the transaction save endpoint. The sensitive data disclosed includes bank account name, bank name, and the last four digits of the card. This occurs because the application does not verify company ownership before persisting and rendering this information. Join the discussion | CVE Database V5 | 08/21/2026, 12:12:59 UTC Added: 08/21/2026, 12:38:05 UTC |
0 CVE-2026-77759 is an authorization bypass vulnerability in Roskus Prospero Flow CRM versions 5.0.0 through 5.3.5. It allows an authenticated user to access transaction data belonging to other companies on the same instance by manipulating the transaction ID in the API request. The flaw exists because the transaction API does not enforce company scoping or permission checks when resolving transaction identifiers. Join the discussion | CVE Database V5 | 08/21/2026, 11:29:43 UTC Added: 08/21/2026, 12:07:43 UTC |
Use of Hard-coded Credentials in the human resources component in Roskus Prospero Flow CRM before 5.15.9 allows unauthenticated remote attackers to authenticate as any employee onboarded through the standard flow, knowing only their email address, because the employee save controller falls back to the literal password "changeme" and the onboarding form provides no password field. Join the discussion | CVE Database V5 | 08/14/2026, 14:00:55 UTC Added: 08/14/2026, 14:27:14 UTC |
0 CVE-2026-19870 is an authorization bypass vulnerability in the payroll module of Roskus Prospero Flow CRM versions before 5.15.10. Authenticated users with read payroll permission can view salary and banking details of employees from other companies within the same instance. Additionally, users with create payroll permission can create payroll records for employees of other companies. This occurs because the system does not properly scope queries to the caller's company and validates employee identifiers only for global existence rather than company membership. Join the discussion | CVE Database V5 | 08/14/2026, 12:08:30 UTC Added: 08/14/2026, 12:27:01 UTC |
0 Missing Authorization and Authorization Bypass Through User-Controlled Key in the product management component in Roskus Prospero Flow CRM before 5.4.7 allows authenticated users of any company to read the full sensitive data (price, cost, stock, SKU, and barcode) of another company's product and to hijack that product by reassigning its company_id, via the product's numeric identifier, because `ProductUpdateController` did not extend `MainController` and therefore required no authentication check on the read endpoint, and `ProductRepository::save()` retrieved the record via `Product::find($data['id'])` without constraining the query to the authenticated user's company before overwriting its company_id. Join the discussion | CVE Database V5 | 08/13/2026, 14:04:55 UTC Added: 08/13/2026, 14:26:46 UTC |
Authorization Bypass Through User-Controlled Key in the ticket management component in Roskus Prospero Flow CRM before 5.4.9 allows authenticated users of any company to read the full content (title, description, and attachments) of tickets belonging to another company, to hijack another company's tickets by reassigning their company_id, and to delete another company's tickets without any authorization check, via the ticket's numeric identifier, because the read and save operations retrieve the record without constraining the query to the authenticated user's company, and the delete controller type-hints a generic Illuminate\Http\Request instead of the TicketDeleteRequest that would enforce the required permission. Join the discussion | CVE Database V5 | 08/11/2026, 13:54:05 UTC Added: 08/11/2026, 14:12:16 UTC |
Showing 1 to 10 of 19 results