Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
Admidio versions before 5.0.11 contain a reflected cross-site scripting vulnerability in the SSO/SAML endpoint that echoes unencoded exception… (CVE-2026-69092)CVE-2026-69092 0 Admidio versions before 5.0.11 have a reflected cross-site scripting (XSS) vulnerability in the SSO/SAML endpoint. This vulnerability occurs because unencoded exception messages are echoed in HTTP responses. Unauthenticated attackers can exploit this by injecting arbitrary JavaScript via SAML Issuer elements or LightSaml library parameters, potentially executing code in users' browsers and hijacking sessions. Join the discussion | GCVE Database | 08/03/2026, 15:32:48 UTC Added: 08/03/2026, 21:21:44 UTC |
Admidio before 5.0.11 fails to validate target organization membership in role handlers, allowing authenticated role administrators to delete,… (CVE-2026-69090)CVE-2026-69090 0 Admidio versions prior to 5.0.11 contain a vulnerability where role handlers do not properly validate the target organization's membership. This flaw allows authenticated role administrators to manipulate roles of other organizations by supplying a role UUID from a different organization. Actions such as deleting, activating, deactivating, or editing roles can be performed without proper authorization. The vulnerability has a CVSS score of 4.9, indicating medium severity. Join the discussion | GCVE Database | 08/03/2026, 15:32:48 UTC Added: 08/03/2026, 21:21:44 UTC |
Admidio before 5.0.11 contains an authentication bypass vulnerability in the forum module when configured in login-only mode. (CVE-2026-69091)CVE-2026-69091 0 Admidio versions prior to 5.0.11 have an authentication bypass vulnerability in the forum module when it is configured in login-only mode. This flaw allows unauthenticated attackers to access forum topics and posts by exploiting improper access control checks in the module's code. The vulnerability does not affect the integrity or availability of the system but exposes confidential forum content to unauthorized users. Join the discussion | GCVE Database | 08/03/2026, 15:32:48 UTC Added: 08/03/2026, 21:21:43 UTC |
Admidio before 5.0.11 contains an insecure direct object reference vulnerability in the save_temporary mode of mylist_function.php that allows… (CVE-2026-69094)CVE-2026-69094 0 Admidio versions before 5.0.11 have an insecure direct object reference vulnerability in the save_temporary mode of mylist_function.php. Authenticated users can exploit this flaw to hijack list configurations by enumerating global list UUIDs and overwriting admin-curated global lists or other users' private lists. This allows attackers to transfer ownership and demote global lists to personal configurations. The vulnerability has a CVSS 3.1 score of 4.3, indicating medium severity. Join the discussion | GCVE Database | 08/03/2026, 15:32:49 UTC Added: 08/03/2026, 21:21:42 UTC |
Admidio before 5.0.11 does not validate the adm_csrf_token in modules/category-report/preferences.php, which performs persistent Category Report… (CVE-2026-69093)CVE-2026-69093 0 Admidio versions before 5.0.11 contain a vulnerability in the modules/category-report/preferences.php file where the adm_csrf_token is not validated. This allows an attacker to trick an authenticated administrator into visiting a crafted URL that can delete or duplicate Category Report configurations. The flaw affects the integrity and availability of the Category Report module's configuration. The vulnerability has a CVSS 3.1 score of 4.6, indicating a medium severity impact primarily on integrity and availability with low attack complexity but requiring some user interaction and privileges. Join the discussion | GCVE Database | 08/03/2026, 15:32:49 UTC Added: 08/03/2026, 21:21:42 UTC |
Showing 1 to 5 of 5 results