Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
CVE-2026-4533 is a medium severity SQL injection vulnerability found in version 1.0 of the code-projects Simple Food Ordering System, specifically in the all-tickets.php file. The vulnerability arises from improper sanitization of the 'Status' parameter, allowing remote attackers to inject malicious SQL commands without authentication or user interaction. Although the exploit code is publicly available, there are no confirmed reports of active exploitation in the wild. Successful exploitation could lead to unauthorized data access or modification within the affected database, impacting confidentiality and integrity. The vulnerability affects a niche food ordering system product, limiting its widespread impact but posing risks to organizations using this software. Mitigation requires immediate input validation and parameterized queries in the affected code, along with monitoring and restricting access to the vulnerable endpoint. Countries with notable usage of this software or similar web applications, including the United States, India, United Kingdom, Canada, Australia, and Germany, may face higher risks. Organizations should prioritize patching or applying workarounds to prevent potential data breaches or service disruptions. Join the discussion | CVE Database V5 | 03/22/2026, 02:02:11 UTC Added: 03/22/2026, 02:30:50 UTC |
0 CVE-2026-4532 is a medium severity vulnerability affecting code-projects Simple Food Ordering System version 1.0. It allows remote attackers to access files or directories via the /food/sql/food.sql file in the Database Backup Handler component. The vulnerability requires no authentication or user interaction and can be exploited over the network. Although the exploit has been publicly disclosed, no known active exploitation in the wild has been reported. The vulnerability could lead to unauthorized disclosure of sensitive data stored in accessible files or directories. Organizations using this software should review and change configuration settings to mitigate risk. Due to the limited scope of the affected product and version, the impact is relatively contained but still significant for affected deployments. The CVSS 4. Join the discussion | CVE Database V5 | 03/22/2026, 01:32:14 UTC Added: 03/22/2026, 01:45:50 UTC |
A security flaw has been discovered in code-projects Simple Food Ordering System 1.0. This issue affects some unknown processing of the file /addproduct.php. Performing manipulation of the argument photo results in unrestricted upload. The attack may be initiated remotely. The exploit has been released to the public and may be exploited. Join the discussion | CVE Database V5 | 10/28/2025, 05:32:05 UTC Added: 10/28/2025, 06:05:15 UTC |
A vulnerability was detected in code-projects Simple Food Ordering System 1.0. The affected element is an unknown function of the file /editproduct.php. Performing manipulation of the argument pname/category/price results in cross site scripting. The attack may be initiated remotely. The exploit is now public and may be used. Join the discussion | CVE Database V5 | 10/27/2025, 18:02:06 UTC Added: 10/27/2025, 18:22:45 UTC |
A security vulnerability has been detected in code-projects Simple Food Ordering System 1.0. Impacted is an unknown function of the file /editproduct.php. Such manipulation of the argument photo leads to unrestricted upload. The attack can be launched remotely. The exploit has been disclosed publicly and may be used. Join the discussion | CVE Database V5 | 10/27/2025, 17:32:08 UTC Added: 10/27/2025, 17:37:46 UTC |
A weakness has been identified in code-projects Simple Food Ordering System 1.0. This issue affects some unknown processing of the file /addcategory.php. This manipulation of the argument cname causes cross site scripting. The attack can be initiated remotely. The exploit has been made available to the public and could be exploited. Join the discussion | CVE Database V5 | 10/27/2025, 17:32:05 UTC Added: 10/27/2025, 17:37:46 UTC |
CVE-2025-12299 is a medium severity cross-site scripting (XSS) vulnerability found in version 1.0 of the code-projects Simple Food Ordering System. The flaw exists in the /addproduct.php file, where manipulation of the pname, category, or price parameters allows remote attackers to inject malicious scripts. Exploitation does not require authentication but does require user interaction, such as a victim visiting a crafted URL. Although no known exploits are currently observed in the wild, the exploit code has been publicly released, increasing the risk of attacks. The vulnerability can lead to theft of user credentials, session hijacking, or defacement of web content. European organizations using this software, especially in the hospitality or food service sectors, may face targeted attacks. Mitigation involves sanitizing and validating all user inputs on the affected parameters and applying patches once available. Countries with higher adoption of small to medium hospitality businesses using this software, such as Germany, France, Italy, and Spain, are more likely to be impacted. Join the discussion | CVE Database V5 | 10/27/2025, 17:02:09 UTC Added: 10/27/2025, 17:07:44 UTC |
CVE-2025-12298 is a medium severity cross-site scripting (XSS) vulnerability in version 1.0 of the code-projects Simple Food Ordering System, specifically in the /editcategory.php file via the pname parameter. The vulnerability allows remote attackers to inject malicious scripts without requiring authentication, though user interaction is needed to trigger the attack. Exploits are publicly available, increasing the risk of exploitation. While no known active exploitation has been reported, affected systems remain vulnerable. The impact primarily concerns client-side attacks such as session hijacking, credential theft, or defacement. European organizations using this software, especially in the food service sector, should prioritize patching or mitigating this issue. Countries with higher adoption of this product or with strategic food service industries are more likely to be affected. Mitigations include input validation, output encoding, and deploying web application firewalls tailored to detect XSS payloads. Join the discussion | CVE Database V5 | 10/27/2025, 17:02:06 UTC Added: 10/27/2025, 17:07:44 UTC |
Showing 1 to 8 of 8 results