Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
0 LORIS (Longitudinal Online Research and Imaging System) is a self-hosted web application that provides data- and project-management for neuroimaging research. Prior to 27.0.3 and 28.0.1, the redirect parameter upon login to LORIS was not validating the value of the redirect as being within LORIS, which could be used to trick users into visiting arbitrary URLs if they are given a link with a third party redirect parameter. This vulnerability is fixed in 27.0.3 and 28.0.1. Join the discussion | CVE Database V5 | 04/09/2026, 17:08:49 UTC Added: 04/10/2026, 00:25:29 UTC |
0 LORIS (Longitudinal Online Research and Imaging System) is a self-hosted web application that provides data- and project-management for neuroimaging research. From 24.0.0 to before 27.0.3 and 28.0.1, an incorrect order of operations in the FilesDownloadHandler could result in an attacker escaping the intended download directories. This vulnerability is fixed in 27.0.3 and 28.0.1. Join the discussion | CVE Database V5 | 04/08/2026, 18:28:30 UTC Added: 04/08/2026, 20:35:52 UTC |
0 LORIS (Longitudinal Online Research and Imaging System) is a self-hosted web application that provides data- and project-management for neuroimaging research. From 15.10 to before 27.0.3 and 28.0.1, there is a potential for a cross-site scripting attack in the survey_accounts module if a user provides an invalid visit label. While the data is properly JSON encoded, the Content-Type header is not set causing the web browser to interpret the payload as HTML, opening the possibility of a cross-site scripting if a user is tricked into following an invalid link. This vulnerability is fixed in 27.0.3 and 28.0.1. Join the discussion | CVE Database V5 | 04/08/2026, 18:27:17 UTC Added: 04/09/2026, 05:19:53 UTC |
0 CVE-2026-35169 is a high-severity vulnerability in the aces LORIS web application affecting versions before 27.0.3 and between 28.0.0 and 28.0.1. The help_editor module did not properly sanitize certain user-supplied input, leading to a reflected cross-site scripting (XSS) vulnerability. This flaw could allow an attacker to execute arbitrary scripts if a user is tricked into following a malicious link. Additionally, the same input vector could enable an attacker to download arbitrary markdown files from an unpatched server. Join the discussion | CVE Database V5 | 04/08/2026, 18:24:27 UTC Added: 04/09/2026, 05:19:53 UTC |
0 LORIS (Longitudinal Online Research and Imaging System) is a self-hosted web application that provides data- and project-management for neuroimaging research. From 21.0.0 to before 27.0.3 and 28.0.1, while the document_repository frontend was restricting file access, the backend endpoint was not correctly verifying access permissions. A user could theoretically download a file that they should not have access to, if they know or can brute force the filename. This vulnerability is fixed in 27.0.3 and 28.0.1. Join the discussion | CVE Database V5 | 04/08/2026, 18:23:34 UTC Added: 04/08/2026, 20:35:52 UTC |
0 LORIS (Longitudinal Online Research and Imaging System) is a self-hosted web application that provides data- and project-management for neuroimaging research. From 16.1.0 to before 27.0.3 and 28.0.1, While the frontend of the media module filters files that the user should not have access to, the backend was not applying access checks and it would be possible for someone who should not have access to a file to access it if they know the filename. This vulnerability is fixed in 27.0.3 and 28.0.1. Join the discussion | CVE Database V5 | 04/08/2026, 18:22:09 UTC Added: 04/09/2026, 05:19:53 UTC |
0 LORIS, a self-hosted web application for neuroimaging research data management, contains a directory traversal vulnerability in its static file router in versions from 20.0.0 up to but not including 27.0.3, and from 28.0.0 up to but not including 28.0.1. This flaw allows attackers to access files outside the intended directories via static, css, and js endpoints. Join the discussion | CVE Database V5 | 04/08/2026, 17:57:35 UTC Added: 04/09/2026, 05:19:57 UTC |
0 LORIS (Longitudinal Online Research and Imaging System) is a self-hosted web application that provides data- and project-management for neuroimaging research. Prior to 27.0.3 and 28.0.1, a SQL injection has been identified in some code sections for the MRI feedback popup window of the imaging browser. Attackers can use SQL ingestion to access/alter data on the server. This vulnerability is fixed in 27.0.3 and 28.0.1. Join the discussion | CVE Database V5 | 04/08/2026, 17:47:32 UTC Added: 04/08/2026, 19:50:52 UTC |
0 LORIS (Longitudinal Online Research and Imaging System) is a self-hosted web application that provides data- and project-management for neuroimaging research. Starting in version 24.0.0 and prior to versions 26.0.5, 27.0.2, and 28.0.0, an authenticated user with the appropriate authorization can read configuration files on the server by exploiting a path traversal vulnerability. Some of these files contain hard-coded credentials. The vulnerability allows an attacker to read configuration files containing hard-coded credentials. The attacker could then authenticate to the database or other services if those credentials are reused. The attacker must be authenticated and have the required permissions. However, the vulnerability is easy to exploit and the application source code is public. This problem is fixed in LORIS v26.0.5 and v27.0.2 and above, and v28.0.0 and above. As a workaround, the electrophysiogy_browser in LORIS can be disabled by an administrator using the module manager. Join the discussion | CVE Database V5 | 02/25/2026, 21:26:00 UTC Added: 02/25/2026, 21:56:34 UTC |
0 LORIS (Longitudinal Online Research and Imaging System) is a self-hosted web application that provides data- and project-management for neuroimaging research. Prior to versions 26.0.5, 27.0.2, and 28.0.0, an authenticated user with sufficient privileges can exploit a path traversal vulnerability to upload a malicious file to an arbitrary location on the server. Once uploaded, the file can be used to achieve remote code execution (RCE). An attacker must be authenticated and have the appropriate permissions to exploit this issue. If the server is configured as read-only, remote code execution (RCE) is not possible; however, the malicious file upload may still be achievable. This problem is fixed in LORIS v26.0.5 and above, v27.0.2 and above, and v28.0.0 and above. As a workaround, LORIS administrators can disable the media module if it is not being used. Join the discussion | CVE Database V5 | 02/25/2026, 21:15:54 UTC Added: 02/25/2026, 21:45:42 UTC |
Showing 1 to 10 of 10 results