Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
0 Cockpit CMS 2.14.0 and prior contains a command injection vulnerability in the FFmpeg integration that allows authenticated users with only the assets/upload permission to execute arbitrary commands by uploading a video file with a shell metacharacter-laden filename. The unsanitized filename is interpolated into a shell command executed via Process::fromShellCommandline() before the slugify() sanitizer runs, enabling injected shell metacharacters such as backticks, $(), and semicolons to escape the FFmpeg command context and execute as the web-server user. Join the discussion | CVE Database V5 | 08/14/2026, 19:56:32 UTC Added: 08/14/2026, 20:11:47 UTC |
0 Cockpit CMS through 2.14.0 contains a path traversal and local file inclusion vulnerability that allows unauthenticated attackers to read arbitrary files or execute PHP files by including unvalidated PATH_INFO derived from REQUEST_URI in filesystem path construction without containment checks. Attackers can inject dot-dot sequences into the URL to traverse outside the designated spaces directory, and when the resolved path ends with a .php extension, the application passes it to include(), enabling local file inclusion on deployments using the PHP built-in server or certain non-default Nginx configurations. Join the discussion | CVE Database V5 | 07/02/2026, 20:04:56 UTC Added: 07/02/2026, 20:21:56 UTC |
0 Cockpit CMS through version 2.14.0, patched in commit 72a83fc, contains a stored cross-site scripting vulnerability in the Set field type's Display template option, where the template string is processed by the $interpolate function using new Function() and rendered via Vue's v-html directive without sanitization. An attacker with content/:models/manage permission can inject arbitrary JavaScript into the Display template, which executes in the browser of any user viewing the collection items list. Join the discussion | CVE Database V5 | 05/15/2026, 16:33:46 UTC Added: 05/15/2026, 17:22:45 UTC |
0 Cockpit versions 2.13.5 and earlier contain a critical vulnerability that allows arbitrary code execution through the filter parameter in multiple endpoints. This occurs via the MongoLite $func operator, enabling attackers to execute system commands on the underlying infrastructure without authentication. The vulnerability has a CVSS score of 9.8, indicating a critical severity with high impact on confidentiality, integrity, and availability. No official patch or remediation guidance is currently available, and no known exploits have been reported in the wild. Join the discussion | CVE Database V5 | 04/29/2026, 00:00:00 UTC Added: 04/30/2026, 01:53:38 UTC |
0 Cockpit 2.13.5 and earlier is vulnerable to directory traversal via the Buckets component. This vulnerability allows authenticated attackers to write files to arbitrary locations within the uploads directory or overwrite assets with malicious versions. Join the discussion | CVE Database V5 | 04/29/2026, 00:00:00 UTC Added: 04/29/2026, 20:36:23 UTC |
0 Cockpit 2.13.5 and earlier is affected by a misconfiguration within the Bucket component _isFileTypeAllowed function where a specially crafted filename bypasses an extension filter. This allows an authenticated attacker to rename arbitrary files with the .php file extension enabling arbitrary code to be executed on the underlying server. Join the discussion | CVE Database V5 | 04/29/2026, 00:00:00 UTC Added: 04/29/2026, 20:36:23 UTC |
0 A vulnerability was detected in Cockpit-HQ Cockpit up to 2.13.5. Affected by this issue is some unknown functionality of the component Asset Handler/Aggregate Handler. The manipulation results in improper neutralization of special elements in data query logic. It is possible to launch the attack remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. Join the discussion | CVE Database V5 | 04/20/2026, 09:45:12 UTC Added: 04/20/2026, 10:16:05 UTC |
0 Cockpit is a headless content management system. Any Cockpit CMS instance running version 2.13.4 or earlier with API access enabled is potentially affected by a a SQL Injection vulnerability in the MongoLite Aggregation Optimizer. Any deployment where the `/api/content/aggregate/{model}` endpoint is publicly accessible or reachable by untrusted users may be vulnerable, and attackers in possession of a valid read-only API key (the lowest privilege level) can exploit this vulnerability — no admin access is required. An attacker can inject arbitrary SQL via unsanitized field names in aggregation queries, bypass the `_state=1` published-content filter to access unpublished or restricted content, and extract unauthorized data from the underlying SQLite content database. This vulnerability has been patched in version 2.13.5. The fix applies the same field-name sanitization introduced in v2.13.3 for `toJsonPath()` to the `toJsonExtractRaw()` method in `lib/MongoLite/Aggregation/Optimizer.php`, closing the injection vector in the Aggregation Optimizer. Join the discussion | CVE Database V5 | 03/18/2026, 02:58:12 UTC Added: 03/18/2026, 03:28:22 UTC |
Versions of the package cockpit-hq/cockpit before 2.4.1 are vulnerable to Arbitrary File Upload where an attacker can use different extension to bypass the upload filter. Join the discussion | CVE Database V5 | 02/05/2025, 05:00:16 UTC Added: 07/24/2026, 15:53:01 UTC |
Showing 1 to 9 of 9 results