Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
0 Trix is a what-you-see-is-what-you-get rich text editor for everyday writing. Prior to 2.1.17, Trix is vulnerable to cross-site scripting when a data-trix-serialized-attributes attribute bypasses the DOMPurify sanitizer. An attacker can craft HTML containing a data-trix-serialized-attributes attribute with a malicious payload that, when rendered, executes arbitrary JavaScript in the user's session and may perform unauthorized actions or disclose sensitive information. This issue is fixed in version 2.1.17. Join the discussion | CVE Database V5 | 08/18/2026, 14:24:27 UTC Added: 08/18/2026, 14:35:00 UTC |
0 Trix, a rich text editor by Basecamp, has a stored cross-site scripting (XSS) vulnerability in versions prior to 2.1.18. The issue arises when crafted HTML containing a javascript: URI is pasted into the editor, allowing execution when rendered and clicked by another user. Server-side HTML sanitization can mitigate this risk. The vulnerability is fixed in version 2.1.18. Join the discussion | CVE Database V5 | 08/13/2026, 22:04:19 UTC Added: 08/13/2026, 22:12:00 UTC |
0 Trix is a what-you-see-is-what-you-get rich text editor for everyday writing. Prior to 2.1.18, Trix is vulnerable to cross-site scripting when a crafted application/x-trix-document JSON payload is dropped into an editor using the fallback Level0InputController, such as an embedded WebView without Input Events Level 2 support. The StringPiece.fromJSON method trusts href attributes from the JSON payload without sanitization, allowing a draggable element containing a javascript: URI to bypass DOMPurify sanitization and inject executable JavaScript into the DOM. Exploitation requires the victim to drag and drop attacker-controlled content, and server-side HTML sanitization can neutralize the payload on save. This issue is fixed in version 2.1.18. Join the discussion | CVE Database V5 | 08/12/2026, 20:50:17 UTC Added: 08/12/2026, 21:13:14 UTC |
Showing 1 to 3 of 3 results