Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
0 CVE-2026-71189 is a cross-site scripting (XSS) vulnerability in Toptech Systems TMS7 version 7.6.3. An attacker can craft a request that, when executed by another user, causes attacker-supplied JavaScript to run in the victim's browser within their session context. The vulnerability has a low CVSS score of 3.5, indicating limited impact. There is no information on available patches or vendor advisories. No known exploits are reported in the wild. Join the discussion | CVE Database V5 | 09/29/2026, 21:46:48 UTC Added: 09/29/2026, 21:53:14 UTC |
0 CVE-2026-69662 is a low-severity vulnerability in Toptech Systems TMS7 version 7.6.3 involving unsafe use of inline script execution and string evaluation functions. This flaw could potentially allow limited unauthorized code execution due to unsafe function usage. The vulnerability has a CVSS score of 3.7, indicating low impact with low confidentiality and integrity impact and no availability impact. No known exploits are reported in the wild, and no official patch or remediation guidance is currently available. Join the discussion | CVE Database V5 | 09/29/2026, 21:44:07 UTC Added: 09/29/2026, 21:53:14 UTC |
0 CVE-2026-71302 is a vulnerability in Toptech Systems TMS7 version 7.6.3 where the application accepts user-supplied session identifiers and fails to regenerate the session ID after authentication. This flaw allows an attacker to set a session ID before victim login and reuse it afterward, enabling session takeover. Join the discussion | CVE Database V5 | 09/29/2026, 21:41:11 UTC Added: 09/29/2026, 21:53:16 UTC |
0 CVE-2026-72507 is a critical time-based blind SQL injection vulnerability in Toptech Systems TMS7 version 7.6.3. It affects the "reportType" parameter in the product summary report feature within the balancing reports section. This vulnerability allows an attacker with high privileges to execute unauthorized SQL queries, potentially leading to significant data confidentiality, integrity, and availability impacts. Join the discussion | CVE Database V5 | 09/29/2026, 21:36:53 UTC Added: 09/29/2026, 21:53:16 UTC |
0 CVE-2026-68068 is a critical time-based blind SQL injection vulnerability in Toptech Systems TMS7 version 7.6.3. It affects the "screenID" parameter in the electronic transaction queue viewer feature within the manual transactions section. The vulnerability allows an attacker with high privileges to execute unauthorized SQL queries, potentially leading to high confidentiality impact, limited integrity impact, and high availability impact. Join the discussion | CVE Database V5 | 09/29/2026, 21:33:47 UTC Added: 09/29/2026, 21:53:14 UTC |
0 CVE-2026-68954 is a critical time-based blind SQL injection vulnerability in the 'pattern' parameter of the search function on the home page of Toptech Systems TMS7 version 7.6.3. This vulnerability allows an attacker with high privileges to execute unauthorized SQL queries, potentially leading to high confidentiality impact, limited integrity impact, and high availability impact. Join the discussion | CVE Database V5 | 09/29/2026, 21:32:05 UTC Added: 09/29/2026, 21:53:14 UTC |
0 CVE-2026-63713 is a critical time-based blind SQL injection vulnerability in Toptech Systems TMS7 version 7.6.3. It affects the "search" parameter in the view audit logs feature within the utilities section. This vulnerability allows an attacker with high privileges to execute unauthorized SQL queries, potentially leading to high confidentiality impact, limited integrity impact, and high availability impact. Join the discussion | CVE Database V5 | 09/29/2026, 21:30:32 UTC Added: 09/29/2026, 21:37:56 UTC |
0 CVE-2026-72510 is a critical SQL injection vulnerability in Toptech Systems TMS7 version 7.6.3. The issue exists in the "supplier_no" parameter of the business allocation search feature, allowing time-based blind SQL injection attacks. This vulnerability can lead to high confidentiality impact, partial integrity compromise, and high availability impact. No patch or official fix information is currently provided. Join the discussion | CVE Database V5 | 09/29/2026, 21:28:26 UTC Added: 09/29/2026, 21:37:56 UTC |
0 CVE-2026-70356 is a critical vulnerability in Toptech Systems TMS7 version 7.6.3 where the file upload endpoint does not enforce server-side file type restrictions. This flaw allows an attacker with high privileges to upload and execute arbitrary PHP files on the web server, potentially leading to full compromise of confidentiality, integrity, and availability. Join the discussion | CVE Database V5 | 09/29/2026, 21:26:22 UTC Added: 09/29/2026, 21:37:56 UTC |
0 CVE-2026-71379 is a critical vulnerability in Toptech Systems TMS7 version 7.6.3 where the file export endpoint allows unauthenticated attackers to export arbitrary database tables via crafted POST requests. This flaw leads to complete confidentiality, integrity, and availability compromise of the affected system. Join the discussion | CVE Database V5 | 09/29/2026, 21:23:25 UTC Added: 09/29/2026, 21:37:56 UTC |
Showing 1 to 10 of 10 results