Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
Dozzle is a realtime log viewer for docker containers. From 10.5.2 until 10.6.15, the isBlockedIP SSRF guard in internal/notification/dispatcher/webhook.go, used by safeDialContext for webhook notification URLs, does not inspect IPv4 addresses embedded in 6to4, NAT64, Teredo, or IPv4-compatible IPv6 addresses, allowing an authenticated user to reach loopback or link-local targets that the guard intends to block. This issue is fixed in version 10.6.15. Join the discussion | CVE Database V5 | 08/11/2026, 16:52:13 UTC Added: 08/11/2026, 17:13:39 UTC |
Dozzle is a realtime log viewer for docker containers. Prior to 10.5.2, in a default dozzle deploy (the documented quickstart, no DOZZLE_AUTH_PROVIDER set), POST /api/notifications/test-webhook is reachable without authentication and forwards an attacker-controlled URL into a WebhookDispatcher that sends an HTTP POST to the supplied URL with attacker-controlled request headers, and returns the response status code AND up to 1MB of the response body to the caller, when the target replies non-2xx. This vulnerability is fixed in 10.5.2. Join the discussion | CVE Database V5 | 05/26/2026, 22:01:29 UTC Added: 05/26/2026, 22:18:34 UTC |
Dozzle versions prior to 10.5.2 contain an origin validation vulnerability in the WebSocket upgrader for the /exec and /attach endpoints. The CheckOrigin function accepts requests from any origin, combined with a JWT cookie set with SameSite: Lax, enabling Cross-Site WebSocket Hijacking (CSWSH). An attacker on a same-site origin can exploit this to gain interactive shell access to containers accessible by the victim. This vulnerability is fixed in version 10.5.2. Join the discussion | CVE Database V5 | 05/26/2026, 21:58:55 UTC Added: 05/26/2026, 22:18:34 UTC |
CVE-2026-24740 is a high-severity improper access control vulnerability in Dozzle, a realtime log viewer for Docker containers. Versions prior to 9.0.3 allow users restricted by label filters to bypass these restrictions and obtain an interactive root shell in containers outside their authorized scope by directly targeting container IDs. This flaw enables privilege escalation within the same host, potentially compromising container integrity and confidentiality. The vulnerability requires no user interaction and can be exploited remotely over the network with low complexity. Although no known exploits are currently in the wild, affected users should upgrade to Dozzle 9.0.3 immediately to mitigate risk. European organizations using Dozzle in containerized environments are at risk, especially those with multi-tenant or segmented container deployments. Join the discussion | CVE Database V5 | 01/27/2026, 20:59:05 UTC Added: 01/27/2026, 21:05:59 UTC |
Showing 1 to 4 of 4 results