Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
0 Budibase versions 3.39.4 before 3.40.0 contain an authorization regression in the S3 attachment upload endpoint that allows BASIC users to obtain S3 PutObject presigned URLs by sending POST requests to the attachments endpoint. The route was changed from a BUILDER permission check to a TABLE/WRITE check, which BASIC users hold by default. Attackers can specify arbitrary S3 buckets in the request body to generate presigned URLs for writing to any bucket accessible by the stored IAM credentials, enabling unauthorized file uploads. Join the discussion | CVE Database V5 | 08/14/2026, 11:35:43 UTC Added: 08/14/2026, 11:56:54 UTC |
Budibase server versions prior to 3.40.0 contain a server-side request forgery (SSRF) vulnerability that affects OpenAPI query import and REST query execution. Authenticated builder-level users can exploit this flaw to bypass DNS pinning protections via DNS rebinding attacks. This allows attackers to configure hostnames that initially resolve to public IP addresses during validation but later resolve to loopback or private IP addresses during actual connection, enabling access to internal HTTP services that should be blocked. Join the discussion | CVE Database V5 | 08/13/2026, 21:54:44 UTC Added: 08/13/2026, 22:12:00 UTC |
0 Budibase server versions prior to 3.40.0 contain an unauthenticated SQL injection vulnerability in webhook-triggered automations that use EXECUTE_QUERY steps. This allows attackers to send crafted JSON payloads to webhook endpoints, injecting SQL commands that execute with database credentials configured by the builder. The vulnerability can lead to unauthorized data exfiltration, modification, and persistence in connected datasources such as Snowflake. The vulnerability has a critical severity rating with a CVSS score of 9. A patch is available, and since this is a cloud service, the vendor manages remediation server-side. Join the discussion | CVE Database V5 | 08/13/2026, 21:54:43 UTC Added: 08/13/2026, 22:12:00 UTC |
0 CVE-2026-72850 is a critical path traversal vulnerability in Budibase server versions before 3.40.0. It allows authenticated users with builder privileges to upload files with crafted filenames containing traversal sequences (e.g., '..') that are not properly sanitized. These sequences are preserved during workspace export, enabling attackers to write arbitrary content to any path writable by the Budibase process. The vulnerability has a high CVSS 4.0 score of 9.4, indicating severe impact. Budibase is a cloud service, and a patch is available for this issue. Join the discussion | CVE Database V5 | 08/13/2026, 21:54:42 UTC Added: 08/13/2026, 22:12:00 UTC |
Budibase before 3.40.0 contains a cross-site request forgery vulnerability in the chat-link handoff endpoint that allows attackers to bind an external chat identity to a victim's account. Attackers can craft a phishing page that auto-submits a POST request with a leaked confirmation token to bind their chat identity to a victim user's account, enabling impersonation within agent operations and inheritance of victim permissions. Join the discussion | CVE Database V5 | 08/13/2026, 21:54:41 UTC Added: 08/13/2026, 22:12:00 UTC |
0 Budibase Server before 3.40.0 contains a NoSQL injection vulnerability in the MongoDB query execution endpoint where user-supplied parameters are interpolated into JSON query templates without proper sanitization of JSON metacharacters. Attackers with query write permission can inject JSON structural characters to alter MongoDB queries, bypassing filters to read, modify, or delete arbitrary documents. Join the discussion | CVE Database V5 | 08/13/2026, 11:28:19 UTC Added: 08/13/2026, 12:52:11 UTC |
0 Budibase before 3.40.0 contains a NoSQL injection vulnerability in the MongoDB datasource integration where user-supplied parameters are enriched with handlebars using noEscaping: true and parsed without operator filtering. Attackers can inject MongoDB operators through query parameters to bypass per-user access controls, read arbitrary documents, execute JavaScript via $where operators, or modify collections through update and delete operations. Join the discussion | CVE Database V5 | 08/13/2026, 11:28:19 UTC Added: 08/13/2026, 12:52:11 UTC |
Budibase before 3.38.1 contains a server-side request forgery vulnerability in the REST datasource integration that fails to validate HTTP redirects against the IP blacklist. Attackers with Builder role can configure a REST datasource pointing to an external server that returns a redirect to internal IP addresses, bypassing blacklist protection to access cloud metadata endpoints and internal services. Join the discussion | GCVE Database | 08/01/2026, 15:30:27 UTC Added: 08/01/2026, 21:18:12 UTC |
Budibase, an open-source low-code platform for building internal applications, has multiple vulnerabilities that allow manipulation of files. These issues affect versions up to and including 3.39.0. No CVSS score is provided, and no known exploits are reported in the wild. The vulnerabilities were published by the Bundesamt für Sicherheit in der Informationstechnik. No patch or remediation information is currently available. Join the discussion | GCVE Database | 05/27/2026, 22:00:00 UTC Added: 06/29/2026, 22:11:13 UTC |
A vulnerability identified as CVE-2026-45717 affects Budibase, an open-source low-code platform used for creating internal applications such as admin panels. The issue allows an attacker to bypass security controls. The affected versions include Budibase versions prior to 3.38.1. There is no CVSS score available, no known exploits in the wild, and no patch or remediation information provided by the vendor. The vulnerability was published by the Bundesamt für Sicherheit in der Informationstechnik. Due to the lack of detailed technical information and absence of a vendor advisory specifying a fix, the patch status is not confirmed. Join the discussion | GCVE Database | 05/17/2026, 22:00:00 UTC Added: 05/28/2026, 20:54:55 UTC |
Showing 1 to 10 of 12 results