Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
0 A HTTP Host header attack vulnerability affects WebClient and the WebScheduler web apps of PcVue in version 15.0.0 through 16.3.3 included, allowing a remote attacker to inject harmful payloads that manipulate server-side behavior. This vulnerability only affects the endpoints /Authentication/ExternalLogin, /Authentication/AuthorizationCodeCallback and /Authentication/Logout of the WebClient and WebScheduler web apps. Join the discussion | CVE Database V5 | 02/26/2026, 07:58:00 UTC Added: 02/26/2026, 08:11:32 UTC |
0 The Secure and SameSite attribute are missing in the GraphicalData web services and WebClient web app of PcVue in version 12.0.0 through 16.3.3 included. Join the discussion | CVE Database V5 | 02/26/2026, 07:57:46 UTC Added: 02/26/2026, 08:11:32 UTC |
Some HTTP security headers are not properly set by the web server when sending responses to the client application. Join the discussion | CVE Database V5 | 02/26/2026, 07:57:29 UTC Added: 02/26/2026, 08:11:32 UTC |
An XSS vulnerability affects the OAuth web services used by the WebVue, WebScheduler, TouchVue and SnapVue features of PcVue in version 12.0.0 through 16.3.3 included. It might allow a remote attacker to trick a legitimate user into loading content from another site upon unsuccessful user authentication on an unknown application (unknown client_id). This vulnerability only affects the error page of the OAuth server. Join the discussion | CVE Database V5 | 02/26/2026, 07:57:11 UTC Added: 02/26/2026, 08:11:32 UTC |
0 HTTP headers are added by the default configuration of IIS and ASP.net, and are not removed at the deployment phase of the webservices used by the WebVue, WebScheduler, TouchVue and SnapVue features of PcVue in version 12.0.0 through 16.3.3 included. It unnecessarily exposes sensitive information about the server configuration. Join the discussion | CVE Database V5 | 02/26/2026, 07:56:57 UTC Added: 02/26/2026, 08:11:32 UTC |
The OAuth grant type Resource Owner Password Credentials (ROPC) flow is still used by the werbservices used by the WebVue, WebScheduler, TouchVue and Snapvue features of PcVue in version 12.0.0 through 16.3.3 included despite being deprecated. It might allow a remote attacker to steal user credentials. Join the discussion | CVE Database V5 | 02/26/2026, 07:56:10 UTC Added: 02/26/2026, 08:11:32 UTC |
A missing origin validation in WebSockets vulnerability affects the GraphicalData web services used by the WebVue, WebScheduler, TouchVue and SnapVue features of PcVue in version 12.0.0 through 16.3.3 included. It might allow a remote attacker to lure a successfully authenticated user to a malicious website. This vulnerability only affects the following two endpoints: GraphicalData/js/signalR/connect and GraphicalData/js/signalR/reconnect. Join the discussion | CVE Database V5 | 02/26/2026, 07:55:18 UTC Added: 02/26/2026, 08:11:32 UTC |
Showing 1 to 7 of 7 results